I want to log alert/session into a pcap if a alert is triggered on a session/packet.
How can I do it
There is development work in progress to do this – see Pcap conditional v2.2.12 by scottfgjordan · Pull Request #6766 · OISF/suricata · GitHub
We expect this work to be included in Suricata 7 if it’s completed in time.
Until we do have that feature, the
payload logging is quite useful. Its base64, but if you can decode it can give you a lot of extra context.