suricata
suricata copied to clipboard
Bug 4786/v4
Link to redmine ticket: https://redmine.openinfosecfoundation.org/issues/5207
Note: This branch has a known failure and is just for an intermediary review. The work is yet to be completed and tested. Known issue is commented where it happens in the code.
Major changes that come along with this branch:
All *bits shall follow the same syntax which was one of the complaints and motivation behind this work.
The syntax shall be
xbits:set,abc,expire 1000, track ip_dst;
hostbits:set,abc,expire 1000, track ip_dst;
flowbits:set,abc;
This makes a huge difference in the currently implemented hostbits
syntax and will break any existing rules that use it. No rules were found in ET rulesets that used hostbits
.
The syntax currently in master
for hostbits
is:
hostbits:set,abc,src
which is an equivalent in terms of functionality to the syntax proposed in this PR:
hostbits:set,abc,expire 300, track ip_src;
WARNING:
field | test | baseline | % |
---|---|---|---|
build_asan |
Pipeline 8456
WARNING:
field | baseline | test | % |
---|---|---|---|
build_asan |
Pipeline 8456
ERROR:
ERROR: QA failed on build_asan.
Pipeline 10596
Replaced w #8205