Xdp tunnel 7674 v10.1#3045
Conversation
1540fc5 to
6e897ea
Compare
6e897ea to
4b40f08
Compare
Ticket: 7674
Allows to check for ebpf compiled filter
Ticket: 7674
4b40f08 to
7b82bc6
Compare
|
Hey, I tried out the live test with your Suri branch xdp-tunnel-7674-v16, and I noticed that the live test passes even though there are no capture-bypassed packets logged by Suricata. Is this expected behavior? I have run it from my Suricata directory such as: And this was the results: This is my eve.json after the test. There is no sign of capture-bypassed packets. I noticed the test passes because in eve.json you check for I also tried adding stats.log to your test, and there is also only the item Could this potentially be an issue with the dummy interface and eBPF? |
|
Not sure there is an issue It takes time to install the bypass when packets for the same flow may already be in the afpacket queue |
Ticket
Redmine ticket: https://redmine.openinfosecfoundation.org/issues/7674
#2969 continuation :
-ttop speed