Skip to content

Commit

Permalink
Suricata PCAP Docs
Browse files Browse the repository at this point in the history
  • Loading branch information
TOoSmOotH committed Mar 11, 2024
1 parent cf5b97f commit 95b126f
Showing 1 changed file with 5 additions and 0 deletions.
5 changes: 5 additions & 0 deletions suricata.rst
Original file line number Diff line number Diff line change
Expand Up @@ -40,6 +40,11 @@ EXTERNAL_NET

By default, EXTERNAL_NET is set to ``any`` (which includes ``HOME_NET``) to detect lateral movement inside your environment. You can modify this default value by going to :ref:`administration` --> Configuration --> suricata --> config --> vars --> address-groups --> EXTERNAL_NET.

PCAP
----

Starting in 2.4.60, users now have the option to migrate PCAP to be captured by Suricata instead of Stenographer. This feature is in BETA There are 2 modes for Suricata PCAP. The first mode is TRANSITION that will keep Stenographer running but not capturing traffic. This allows for retrieval of PCAP frmo older PCAP stored in Steno as well as new PCAP generated from Suricata.

Performance
-----------

Expand Down

0 comments on commit 95b126f

Please sign in to comment.