mirror of https://github.com/OISF/suricata
You cannot select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
20 lines
492 B
ReStructuredText
20 lines
492 B
ReStructuredText
6 years ago
|
Bypass Keyword
|
||
|
==============
|
||
|
|
||
|
Suricata has a ``bypass`` keyword that can be used in signatures to exclude traffic from further evaluation.
|
||
|
|
||
|
The ``bypass`` keyword is useful in cases where there is a large flow expected (e.g. Netflix, Spotify, Youtube).
|
||
|
|
||
|
The ``bypass`` keyword is considered a post-match keyword.
|
||
|
|
||
|
|
||
|
bypass
|
||
|
--------
|
||
|
|
||
|
Bypass a flow on matching http traffic.
|
||
|
|
||
|
Example::
|
||
|
|
||
|
alert http any any -> any any (content:"suricata-ids.org"; \
|
||
|
http_host; bypass; sid:10001; rev:1;)
|