doc: add info about capture_file key

pull/7430/head
Eric Leblond 6 years ago committed by Victor Julien
parent faab853685
commit 6f06f7c22c

@ -473,9 +473,9 @@ By default all packets are logged except:
It is possible to do conditional pcap logging by using the `conditional` It is possible to do conditional pcap logging by using the `conditional`
option in the pcap-log section. By default the variable is set to `all` option in the pcap-log section. By default the variable is set to `all`
so all packet are logged. If the variable is set to `alerts` then only so all packets are logged. If the variable is set to `alerts` then only
the flow with alerts will be logged. If the variable is set to `tag` the flow with alerts will be logged. If the variable is set to `tag`
then only packets tagged by signature using the `tag` keyword will then only packets tagged by signatures using the `tag` keyword will
be logged to the pcap file. Please note that if `alerts` or `tag` is be logged to the pcap file. Please note that if `alerts` or `tag` is
used, then in the case of TCP session, Suricata will use available used, then in the case of TCP session, Suricata will use available
information from the streaming engine to log data that have triggered information from the streaming engine to log data that have triggered

@ -147,6 +147,13 @@ the signature.
} }
}, },
Pcap Field
~~~~~~~~~~
If pcap log capture is active in `multi` mode, a `capture_file` key will be added to the event
with value being the full path of the pcap file where the corresponding packets
have been extracted.
Event type: Anomaly Event type: Anomaly
------------------- -------------------

Loading…
Cancel
Save