Re: Feature #1478

Hi all,

Regarding the titular feature ticket on Redmine - it seems like the requested counter is very close to others that already exist.
flow_mgr.flows_checked - flow_mgr.flows_removed
would seem to give the desired result - the number of active flows after a pass through the hash table.

Am I correct here? And if so, is this something the Suricata community would like added still?

I don’t think this would be a reliable way. The checked number is affected by optimizations where we wouldn’t check entire hash rows worth of flows based on their timestamps.

I don’t think there is a way to get this number currently. I am interested in adding something for sure.