Project

General

Profile

Actions

Feature #5646

open

Task #5645: tracking: elephant flow detection

rules: allow matching on flow pkts and bytes in either direction

Added by Victor Julien almost 2 years ago. Updated 2 months ago.

Status:
In Review
Priority:
High
Target version:
Effort:
Difficulty:
Label:

Description

Probably need some logic to express direction, e.g.

flow.pkts:toserver,>,10000;
flow.pkts:either,=,10000;
flow.bytes:both,>,1G;

Exact syntax TBD.


Related issues 2 (0 open2 closed)

Related to Suricata - Feature #6164: rules: allow matching on flow pkts and bytesClosedPhilippe AntoineActions
Related to Suricata - Feature #7097: Additions to flow detection - sizeClosedOISF DevActions
Actions

Also available in: Atom PDF