[Oisf-users] Aggregated statistics?

Michael J. Sheldon msheldon at godaddy.com
Tue Sep 13 16:56:05 UTC 2016


Is it possible to have Suricata write aggregated traffic statistics?

Specifically, I would like to have protocol-specific counts, per minute.

I've searched, but all I find says that the stats log does not break down by protocol, and the eve/tcpdump logs write for every packet. The traffic levels we sometimes see are not practical for writing every single transaction.

Michael Sheldon
Dev-DNS Services
GoDaddy.com


More information about the Oisf-users mailing list