mirror of https://github.com/OISF/suricata
detect: log app-layer metadata in alert with single tx
Ticket: 7199 Uses a config parameter detect.guess-applayer-tx to enable this behavior (off by default) This feature is requested for use cases with signatures not using app-layer keywords but still targetting application layer transactions, such as pass/drop rule combination, or lua usage. This overrides the previous behavior of checking if the signature has a content match, by checking if there is only one live transaction, in addition to the config parameter being set.pull/12259/head
parent
18ab9a6ccd
commit
f2c3776314
Loading…
Reference in New Issue