[Oisf-users] Suricata's http-log

Victor Julien victor at inliniac.net
Fri Mar 30 14:49:50 UTC 2012


On 03/30/2012 04:48 PM, Peter Manev wrote:
> Please have in mind that Suricata actually logs only properly terminated
> connections in terms of http (FA received, proper tcp teardown).

TCP sessions that time out (no RST or FIN sequence) will be logged as well.

-- 
---------------------------------------------
Victor Julien
http://www.inliniac.net/
PGP: http://www.inliniac.net/victorjulien.asc
---------------------------------------------




More information about the Oisf-users mailing list