]> git.ipfire.org Git - thirdparty/suricata.git/commit
eve/alert: log payload directly from stream buffer
authorVictor Julien <vjulien@oisf.net>
Mon, 20 Nov 2023 09:57:38 +0000 (10:57 +0100)
committerVictor Julien <victor@inliniac.net>
Sat, 16 Mar 2024 16:28:37 +0000 (17:28 +0100)
commit43858f70ad26fe17e2399e3a12c4ee6168f68af1
tree3501963990667cb2e7ed07ce7d1e0b3e097f7f20
parent829bab295b1bdf58c7df00a62b2d083294744b5c
eve/alert: log payload directly from stream buffer

This avoids looping over partly duplicate segments that cause
output data corruption by logging parts of the stream data multiple
times.

For data with GAPs now add a indicator '[4 bytes missing]' similar
to how Wireshark does it.

Bug: #6553.
src/output-json-alert.c