suricata
detect-geoip.h
Go to the documentation of this file.
1
/* Copyright (C) 2012-2019 Open Information Security Foundation
2
*
3
* You can copy, redistribute or modify this Program under the terms of
4
* the GNU General Public License version 2 as published by the Free
5
* Software Foundation.
6
*
7
* This program is distributed in the hope that it will be useful,
8
* but WITHOUT ANY WARRANTY; without even the implied warranty of
9
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10
* GNU General Public License for more details.
11
*
12
* You should have received a copy of the GNU General Public License
13
* version 2 along with this program; if not, write to the Free Software
14
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15
* 02110-1301, USA.
16
*/
17
18
/**
19
* \file
20
*
21
* \author Ignacio Sanchez <sanchezmartin.ji@gmail.com>
22
* \author Bill Meeks <billmeeks8@gmail.com>
23
*/
24
25
#ifndef SURICATA_DETECT_GEOIP_H
26
#define SURICATA_DETECT_GEOIP_H
27
28
#ifdef HAVE_GEOIP
29
30
#include <maxminddb.h>
31
32
#define GEOOPTION_MAXSIZE 3
/* Country Code (2 chars) + NULL */
33
#define GEOOPTION_MAXLOCATIONS 64
34
35
typedef
struct
DetectGeoipData_ {
36
uint8_t location[GEOOPTION_MAXLOCATIONS][GEOOPTION_MAXSIZE];
/** country code for now, null term.*/
37
int
nlocations;
/** number of location strings parsed */
38
uint32_t
flags
;
39
int
mmdb_status;
/** Status of DB open call, MMDB_SUCCESS or error */
40
MMDB_s mmdb;
/** MaxMind DB file handle structure */
41
} DetectGeoipData;
42
43
#endif
44
45
void
DetectGeoipRegister
(
void
);
46
47
#endif
DetectGeoipRegister
void DetectGeoipRegister(void)
Registration function for geoip keyword (no libgeoip support)
Definition:
detect-geoip.c:54
flags
uint8_t flags
Definition:
decode-gre.h:0
src
detect-geoip.h
Generated on Sat Nov 23 2024 23:30:29 for suricata by
1.8.18