You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
suricata/doc/userguide/output
Philippe Antoine f2c3776314 detect: log app-layer metadata in alert with single tx
Ticket: 7199

Uses a config parameter detect.guess-applayer-tx to enable
this behavior (off by default)

This feature is requested for use cases with signatures not
using app-layer keywords but still targetting application
layer transactions, such as pass/drop rule combination,
or lua usage.

This overrides the previous behavior of checking if the signature
has a content match, by checking if there is only one live
transaction, in addition to the config parameter being set.
3 months ago
..
eve detect: log app-layer metadata in alert with single tx 3 months ago
files-json/elk
custom-http-logging.rst
custom-tls-logging.rst tls-log: deprecate 6 months ago
index.rst
log-rotation.rst
lua-output.rst
syslog-alerting-comp.rst