suricata
TxNonPFData Struct Reference
Collaboration diagram for TxNonPFData:

Data Fields

AppProto alproto
 
uint8_t sub_state
 
int dir
 
uint8_t progress
 
int sig_list
 
bool run_always
 
uint32_t sigs_cnt
 
struct PrefilterNonPFDataSig * sigs
 
const char * engine_name
 

Detailed Description

Definition at line 742 of file detect-engine-prefilter.c.

Field Documentation

◆ alproto

AppProto TxNonPFData::alproto

Definition at line 743 of file detect-engine-prefilter.c.

◆ dir

int TxNonPFData::dir

0: toserver, 1: toclient

Definition at line 745 of file detect-engine-prefilter.c.

◆ engine_name

const char* TxNonPFData::engine_name

pointer to name owned by DetectEngineCtx::non_pf_engine_names

Definition at line 755 of file detect-engine-prefilter.c.

◆ progress

uint8_t TxNonPFData::progress

progress state value to register at

Definition at line 746 of file detect-engine-prefilter.c.

◆ run_always

bool TxNonPFData::run_always

the buffer holds a stateful keyword: evaluate its engine on every tx update (engine progress -1) so a provisional miss can be revisited as the transaction advances.

Definition at line 752 of file detect-engine-prefilter.c.

◆ sig_list

int TxNonPFData::sig_list

special handling: normally 0, but for special cases (app-layer-state, app-layer-event) use the list id to create separate engines

Definition at line 747 of file detect-engine-prefilter.c.

◆ sigs

struct PrefilterNonPFDataSig* TxNonPFData::sigs

Definition at line 754 of file detect-engine-prefilter.c.

◆ sigs_cnt

uint32_t TxNonPFData::sigs_cnt

Definition at line 753 of file detect-engine-prefilter.c.

◆ sub_state

uint8_t TxNonPFData::sub_state

Definition at line 744 of file detect-engine-prefilter.c.


The documentation for this struct was generated from the following file: