everyone: I have some questions about the Suricata 7 conditional pcap: 1). with alerts mode, I found that suricata just logged the packet that triggered some specific rules, not the all packets that belongs to one tcp flow, here is the problem, I want the complete flow packets, not just the packet that triggers the rules; 2). with tag mode, I added a tag to my custome rules, when I restarted the suricata engine, it outputed an error something like grammatical error, anyone met the same problem ?
anyone can help or just explain ?