Project

General

Profile

Actions

Feature #385

closed

Configuration option to log all known (pcap) data for a stream when an alert fires

Added by David Wharton about 13 years ago. Updated about 5 years ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

This is a request to be able to configure Suricata to log as much of a stream that it can leading up to an alert. For example, if an alert is generated, this configuration directive would tell Suricata to log as much of the stream that it knows about (e.g. what is in memory) up until and including the data that caused the alert, to disk. Data after an alert can be set by tagging directives but I think it would be handy to be able to configure Suricata to log all traffic it has in memory for a stream that generates an alert. Logging of network data would of course be in libpcap format (see also Feature #384 -- https://redmine.openinfosecfoundation.org/issues/384).


Related issues 4 (2 open2 closed)

Related to Suricata - Task #2309: SuriCon 2017 brainstormAssignedVictor JulienActions
Related to Suricata - Task #2219: Save pcap only if alertRejectedActions
Related to Suricata - Task #2685: SuriCon 2018 brainstormAssignedVictor JulienActions
Is duplicate of Suricata - Feature #120: Capture full session on alertClosedScott JordanActions
Actions

Also available in: Atom PDF