Project

General

Profile

Actions

Documentation #5465

open

doc/userguide: document terminating behavior of rule actions

Added by Victor Julien over 2 years ago. Updated 6 months ago.

Status:
Assigned
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Various actions have different "terminating behaviors" in different scenarios.

e.g.:
alert will not terminate, but is limited to a max number of alerts per packet in the output
pass will immediately stop logging more alerts for the same packet and future alerts in the flow
drop will currently log all alerts for a packet, then drop the rest of the flow


Related issues 2 (2 open0 closed)

Related to Suricata - Documentation #5554: userguide: document behavior for actions like PASS, DROP, REJECT, BYPASS...NewOISF DevActions
Related to Suricata - Documentation #7277: doc/actions: clarify 'pass' scope variationsNewOISF DevActions
Actions

Also available in: Atom PDF