]> git.ipfire.org Git - thirdparty/suricata.git/commit
userguide: explain alert queue behavior and stats
authorJuliana Fajardini <jufajardini@gmail.com>
Wed, 6 Apr 2022 20:06:09 +0000 (17:06 -0300)
committerVictor Julien <vjulien@oisf.net>
Tue, 3 May 2022 07:10:02 +0000 (09:10 +0200)
commit4f9c600bedfba85cdcec11aae21ea25e023eb52b
tree44458ae93620b79a8fc4ff1066aa54074e79ca44
parent0ca01f50031365cb60536887fcf615eb5109d358
userguide: explain alert queue behavior and stats

Added sections along packet-alert-max config section explaining
packet alert queue overflow (when Suri reaches packet alert max), when
alerts are discarded etc.

Since from the user perspective it shouldn't matter how we process the
alert queue, the term "replace" is used, even though there's not exactly
a replacing action happening, with the queue bein pre-processed before
being appended to the Packet.

Also described the associated stats and added an explanation on when to
change packet-alert-max.

Task #5178

(cherry picked from commit 1956dc3d5da5dfdc55e0f8304e815b99bd7567e4)
doc/userguide/configuration/suricata-yaml.rst