Project

General

Profile

Actions

Documentation #5465

open

doc/userguide: document terminating behavior of rule actions

Added by Victor Julien over 2 years ago. Updated 6 months ago.

Status:
Assigned
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Various actions have different "terminating behaviors" in different scenarios.

e.g.:
alert will not terminate, but is limited to a max number of alerts per packet in the output
pass will immediately stop logging more alerts for the same packet and future alerts in the flow
drop will currently log all alerts for a packet, then drop the rest of the flow


Related issues 2 (2 open0 closed)

Related to Suricata - Documentation #5554: userguide: document behavior for actions like PASS, DROP, REJECT, BYPASS...NewOISF DevActions
Related to Suricata - Documentation #7277: doc/actions: clarify 'pass' scope variationsNewOISF DevActions
Actions #1

Updated by Victor Julien over 2 years ago

Once we have fully documented the current behavior we need to consider if the behavior actually makes sense. If changes are needed we can track that in a new ticket.

Actions #2

Updated by Victor Julien over 2 years ago

  • Target version changed from 7.0.0-beta1 to 7.0.0-rc1
Actions #3

Updated by Victor Julien about 2 years ago

  • Target version changed from 7.0.0-rc1 to 7.0.0-rc2
Actions #4

Updated by Juliana Fajardini Reichow almost 2 years ago

  • Tracker changed from Task to Documentation
Actions #5

Updated by Victor Julien almost 2 years ago

  • Target version changed from 7.0.0-rc2 to 8.0.0-beta1
Actions #6

Updated by Victor Julien 6 months ago

  • Assignee changed from Juliana Fajardini Reichow to OISF Dev
Actions #7

Updated by Juliana Fajardini Reichow 20 days ago

  • Related to Documentation #5554: userguide: document behavior for actions like PASS, DROP, REJECT, BYPASS... added
Actions #8

Updated by Juliana Fajardini Reichow 20 days ago

Actions

Also available in: Atom PDF