Optimization #4207
closed
Bug #4941: alerts: 5.0.8/6.0.4 count noalert sigs towards built-in alert limit
Use configurable or more dynamic @ PACKET_ALERT_MAX@
Added by Philippe Antoine almost 4 years ago.
Updated over 2 years ago.
Description
Currently, PACKET_ALERT_MAX
is hardcoded to 15
This turned out to be a problem writing S-V test, with many signatures (different variations of a feature) matching on the same packet
That was HTTP keywords on HTTP2 traffic, where I had one packet containing 3 requests
It would be nice to have this value be configurable from suricata.yaml
- Assignee set to OISF Dev
- Target version changed from TBD to 7.0.0-beta1
- Assignee changed from OISF Dev to Juliana Fajardini Reichow
- Status changed from New to In Progress
- Priority changed from Normal to High
- Parent task set to #4941
- Status changed from In Progress to In Review
- Copied to Optimization #5121: Use configurable or more dynamic @ PACKET_ALERT_MAX@ (5.0.x backport) added
- Copied to Optimization #5125: Use configurable or more dynamic @ PACKET_ALERT_MAX@ (6.0.x backport) added
- Status changed from In Review to Closed
Also available in: Atom
PDF