[Oisf-users] Receive alert in TCP session immediately (ver 3.2.3)

Алексей veslo4 at yandex.ru
Tue Jan 23 18:55:41 UTC 2018


Hi,

I'm using Suricata version 3.2.3. If my rule catches alert in TCP session, I receive notification (log entry in eve.json/alert-debug.log) only after this TCP session is closed. Is it possible to receive notifications immediately, without losing session in Suricata's engine? 


Thanks in advance,
Alex


More information about the Oisf-users mailing list