You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
suricata/doc/userguide/output
Philippe Antoine f2c3776314 detect: log app-layer metadata in alert with single tx
Ticket: 7199

Uses a config parameter detect.guess-applayer-tx to enable
this behavior (off by default)

This feature is requested for use cases with signatures not
using app-layer keywords but still targetting application
layer transactions, such as pass/drop rule combination,
or lua usage.

This overrides the previous behavior of checking if the signature
has a content match, by checking if there is only one live
transaction, in addition to the config parameter being set.
8 months ago
..
eve detect: log app-layer metadata in alert with single tx 8 months ago
files-json/elk
custom-http-logging.rst http-log: deprecate 11 months ago
custom-tls-logging.rst tls-log: deprecate 11 months ago
index.rst
log-rotation.rst doc: removed unified2 output 5 years ago
lua-output.rst userguide: (nit) fix typo in lua-output page 4 years ago
syslog-alerting-comp.rst doc/userguide: spelling 2 years ago