Add payload-only-classtypes filtering to suricata conf to filter payl…#14737
Add payload-only-classtypes filtering to suricata conf to filter payl…#14737Aboussejra wants to merge 1 commit intoOISF:mainfrom
Conversation
…oad dump by classtype if needed
victorjulien
left a comment
There was a problem hiding this comment.
Not convinced the string based design is the best here.
| } | ||
|
|
||
| // Check if classtype in alert matches any in the filter list | ||
| const char *alert_classtype = pa->s->classtype; |
There was a problem hiding this comment.
I'm not too fond of this strcmp loop in a critical path. Can we find a better solution? E.g. a class id in a bitarray or something?
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## main #14737 +/- ##
==========================================
- Coverage 82.17% 82.16% -0.02%
==========================================
Files 1008 1008
Lines 263916 263979 +63
==========================================
+ Hits 216868 216890 +22
- Misses 47048 47089 +41
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
|
Also, this feature requires a ticket that should be mentioned in the commit message |
|
And please reference the previos version of the PR #14726 when opening a new one, describing the changes between both versions |
…oad dump by classtype if needed
Make sure these boxes are checked accordingly before submitting your Pull Request -- thank you.
Contribution style:
https://docs.suricata.io/en/latest/devguide/contributing/contribution-process.html
Our Contribution agreements:
https://suricata.io/about/contribution-agreement/ (note: this is only required once)
Changes (if applicable):
(including schema descriptions)
https://redmine.openinfosecfoundation.org/projects/suricata/issues
Link to ticket: https://redmine.openinfosecfoundation.org/issues/8245
Describe changes:
Provide values to any of the below to override the defaults.
link to the pull request in the respective
_BRANCHvariable.SV_REPO=
SV_BRANCH=OISF/suricata-verify#2895
SU_REPO=
SU_BRANCH=
Old versions #14726
FIxed clang format between two versions