[Oisf-users] Aggregated statistics?
Michael J. Sheldon
msheldon at godaddy.com
Tue Sep 13 16:56:05 UTC 2016
Is it possible to have Suricata write aggregated traffic statistics?
Specifically, I would like to have protocol-specific counts, per minute.
I've searched, but all I find says that the stats log does not break down by protocol, and the eve/tcpdump logs write for every packet. The traffic levels we sometimes see are not practical for writing every single transaction.
More information about the Oisf-users