mirror of https://github.com/OISF/suricata
flow: complete stats for app_layer protocol counters
In the case of a gap, or in the case of a flow where one side is recognized, but the other is not before the end, we still increase the counters to have consistency between jq 'select(.event_type=="flow" and .app_proto=="ftp") | .app_proto' log/eve.json | wc -l jq 'select(.event_type=="stats") | .stats."app_layer".flow.ftp' log/eve.json Ticket: #5769pull/8360/head
parent
cfcb7df9dc
commit
27d2bce1a1
Loading…
Reference in New Issue