You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
suricata/doc/userguide
Yash Datre b800ace56f detect: add tcp.session keyword for unified TCP lifecycle matching
Introduce the tcp.session: keyword that accepts a comma-separated subset
of {setup, established, closing} and matches packets whose TCP session
state falls within the named phases.

This lets a rule writer cover the full TCP lifecycle in one rule instead
of separate flow:not_established + flow:established rules.

Changes:
- New detect-tcp-session.{c,h} with parser, match function, unit tests
- Register DETECT_TCP_SESSION in detect-engine-register.{c,h}
- Add to Makefile.am source list
- Extend engine-analyzer text output for tcp.session:
- Extend firewall.json keyword_info with tcp_session phase values
- Update flow-keywords.rst documentation
- Require TCP protocol and SIG_FLAG_REQUIRE_PACKET at setup

Ticket: 7704
(cherry picked from commit 398687d5d4)
4 days ago
..
3rd-party-integration
_static
appendix doc: adjust for master to main rename 12 months ago
capture-hardware pcap-file: skip setvbuf on non-seekable streams 3 months ago
configuration rfb: limit strings length 4 days ago
devguide devguide: add chapter about exception policies 7 months ago
file-extraction
firewall fw: document config action in FW mode 4 days ago
install doc: adjust for master to main rename 12 months ago
ips doc/userguide: add ips chapter; add concept 1 year ago
licenses
lua ntp: expose logged fields to lua 4 months ago
manpages doc: improve manpage of suricatasc 3 months ago
output eve: add rule generation source to alert record 4 months ago
partials pcap-file: skip setvbuf on non-seekable streams 3 months ago
performance hs: prune stale MPM cache files 6 months ago
plugins doc/ndpi: move ndpi docs to new plugins section 1 year ago
reputation
rule-management doc/reload: Expand rule-reload discussion 1 year ago
rules detect: add tcp.session keyword for unified TCP lifecycle matching 4 days ago
upgrade doc/upgrade: note about dns address swap on responses 1 year ago
.gitignore
Makefile.am userguide/Makefile: don't add "install" to EXTRA_DIST 7 months ago
Makefile.sphinx
README.md
acknowledgements.rst doc: Add missing contributors to ack file 1 year ago
command-line-options.rst
conf.py docs: fix deprecated inclusion of rtd theme path 1 year ago
convert.py
docutils.conf
generate-evedoc.sh
index.rst doc/userguide: add a known issues page 11 months ago
initscripts.rst
install.rst doc: update Rust installation instructions 1 week ago
known-issues.rst doc/userguide: add a known issues page 11 months ago
make-sense-alerts.rst
public-data-sets.rst doc: add more public datasets 6 months ago
quickstart.rst af-packet: remove use-mmap option 1 year ago
requirements.txt
security.rst doc: fix typo /var/run/suricata in file permissions docs. 11 months ago
support-status.rst
unix-socket.rst doc: adjust for master to main rename 12 months ago
upgrade.rst flowbits: add deprecation notice for toggle command 3 months ago
verifying-source-files.rst docs: use correct suricata version mentions 8 months ago
what-is-suricata.rst

README.md

Suricata User Guide

This directory contains the Suricata Guide. The Suricata Developer's guide is included as a chapter of the Guide. The Sphinx Document Generator is used to build the documentation. For a primer os reStructuredText see the reStructuredText Primer.

Verifying Changes

There are a number of output formats to choose from when making the source documentation locally (e.g. html, pdf, man).

The documentation source can be built with make -f Makefile.sphinx html. Substitute the 'html' word for desired output format.

There are different application dependencies based on the output desired.