mirror of https://github.com/OISF/suricata
doc: Update bypass docs to use new keyword format
Ticket: #7143 Update documentation to reflect new sticky buffer keyword formatpull/13035/head
parent
e3c6554ee6
commit
deb761367d
@ -1,19 +1,23 @@
|
|||||||
Bypass Keyword
|
Bypass Keyword
|
||||||
==============
|
==============
|
||||||
|
|
||||||
Suricata has a ``bypass`` keyword that can be used in signatures to exclude traffic from further evaluation.
|
.. role:: example-rule-emphasis
|
||||||
|
|
||||||
The ``bypass`` keyword is useful in cases where there is a large flow expected (e.g. Netflix, Spotify, YouTube).
|
Suricata has a ``bypass`` keyword that can be used in signatures to exclude
|
||||||
|
traffic from further evaluation.
|
||||||
|
|
||||||
The ``bypass`` keyword is considered a post-match keyword.
|
The ``bypass`` keyword is useful in cases where there is a large flow expected
|
||||||
|
(e.g. Netflix, Spotify, YouTube).
|
||||||
|
|
||||||
|
The ``bypass`` keyword is considered a post-match keyword.
|
||||||
|
|
||||||
bypass
|
bypass
|
||||||
------
|
------
|
||||||
|
|
||||||
Bypass a flow on matching http traffic.
|
Bypass a flow on matching http traffic.
|
||||||
|
|
||||||
Example::
|
.. container:: example-rule
|
||||||
|
|
||||||
alert http any any -> any any (content:"suricata.io"; \
|
alert http any any -> any any (http.host; \
|
||||||
http_host; bypass; sid:10001; rev:1;)
|
content:"suricata.io"; :example-rule-emphasis:`bypass;` \
|
||||||
|
sid:10001; rev:1;)
|
||||||
|
Loading…
Reference in New Issue