mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 06:38:20 +00:00

The previous behavior was to accomodate SYN/FIN/RST-filtered traces by not reporting missing data (via the content_gap event) for such connections. The new behavior always reports gaps for connections that are established and terminate normally, but sequence numbers indicate that all data packets of the connection were missed. The behavior can be reverted by redef'ing "detect_filtered_trace".
1.2 KiB
1.2 KiB