You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
suricata/doc/userguide
Juliana Fajardini 1956dc3d5d userguide: explain alert queue behavior and stats
Added sections along packet-alert-max config section explaining
packet alert queue overflow (when Suri reaches packet alert max), when
alerts are discarded etc.

Since from the user perspective it shouldn't matter how we process the
alert queue, the term "replace" is used, even though there's not exactly
a replacing action happening, with the queue bein pre-processed before
being appended to the Packet.

Also described the associated stats and added an explanation on when to
change packet-alert-max.

Task #5178
4 years ago
..
3rd-party-integration
_static
capture-hardware napatech: Added comment indicating that hba will be deprecated 6 years ago
configuration userguide: explain alert queue behavior and stats 4 years ago
devguide devguide: update readme 4 years ago
file-extraction http2: allow filestore to work with HTTP2 6 years ago
licenses
lua userguide: rename pg Lua Scripting->Lua Detection 5 years ago
manpages userguide: update references to Suricata website 5 years ago
output pgsql: add initial support 5 years ago
partials ikev1: rename ikev2 to common ike 5 years ago
performance doc/userguide: sphinx syntax correction 4 years ago
reputation
rule-management doc: Improve grammar, spelling and clarifications 6 years ago
rules doc: add usage of flowbits OR op 4 years ago
setting-up-ipsinline-for-linux
upgrade doc: document removal of unified2 6 years ago
.gitignore
Makefile.am devguide: drop use of mscgen script in builds/make 4 years ago
Makefile.sphinx
README.md devguide: move into userguide as last chapter 4 years ago
acknowledgements.rst
command-line-options.rst doc: Improve grammar, spelling and clarifications 6 years ago
conf.py userguide: dynamically determine copyright date 4 years ago
convert.py
index.rst devguide: move into userguide as last chapter 4 years ago
initscripts.rst doc: Improve grammar, spelling and clarifications 6 years ago
install.rst pcre2: remove PCRE1 as dependency 5 years ago
make-sense-alerts.rst doc: Improve grammar, spelling and clarifications 6 years ago
public-data-sets.rst userguide: update wiresharkwiki in public datasets 5 years ago
quickstart.rst doc/quickstart: use new test url that works 6 years ago
setting-up-ipsinline-for-linux.rst doc: Improve grammar, spelling and clarifications 6 years ago
setting-up-ipsinline-for-windows.rst doc: Improve grammar, spelling and clarifications 6 years ago
unix-socket.rst doc: fix URL for unix-socket python example 6 years ago
upgrade.rst doc/userguide: document ftp max-line-length 4 years ago
what-is-suricata.rst doc: Improve grammar, spelling and clarifications 6 years ago

README.md

Suricata User Guide

This directory contains the Suricata Guide. The Suricata Developer's guide is included as a chapter of the Guide. The Sphinx Document Generator is used to build the documentation. For a primer os reStructuredText see the reStructuredText Primer.

Verifying Changes

There are a number of output formats to choose from when making the source documentation locally (e.g. html, pdf, man).

The documentation source can be built with make -f Makefile.sphinx html. Substitute the 'html' word for desired output format.

There are different application dependencies based on the output desired.