everyone: I have some questions about the Suricata 7 conditional pcap: 1). with alerts mode, I found that suricata just logged the packet that triggered some specific rules, not the all packets that belongs to one tcp flow, here is the problem, I want the complete flow packets, not just the packet that triggers the rules; 2). with tag mode, I added a tag to my custome rules, when I restarted the suricata engine, it outputed an error something like grammatical error, anyone met the same problem ?
anyone can help or just explain ?
I'll try to answer your questions to my best:
As an additional note, we recommend using our forum (https://forum.suricata.io/) for such questions, as it's easier for someone from the Suricata team (or the community) to see questions there here, and it has a more fluid way when it comes to following up on questions ;)