[Oisf-users] Question about suricata pcap logging function.
Cooper F. Nelson
cnelson at ucsd.edu
Mon Dec 16 23:51:44 UTC 2013
-----BEGIN PGP SIGNED MESSAGE-----
I'm interested in potentially indexing the pcap files that suricata
exports. Ideally I would like to roll the pcap files when they are 1Gb
in size and then parse them with my indexing program.
My question is what happens to long-lived TCP flows that could
potentially span multiple files. Does anyone know if suri logs packets
from tcp flows as they arrive, or queues them up and only writes them
when the session is closed or hits the stream cap?
Network Security Analyst
UCSD ACT Security Team
cnelson at ucsd.edu x41042
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.17 (MingW32)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
-----END PGP SIGNATURE-----
More information about the Oisf-users