Actions
Feature #2166
openoutput: log only triggering buffers
Description
When adding to the alert events the protocol buffer, we provide valuable information but logging all of them will cause a serious increase in event size. So we should only log the triggering buffers.
Jason Ish is proposing the following (https://github.com/inliniac/suricata/pull/2663#issuecomment-293952371)
{ "timestamp": ... "alert": ... "buffers": [ { "name": "http_response_body", "data": "....", "data-printable": "...", }, { ....
Updated by Victor Julien over 7 years ago
- Subject changed from Log only triggering buffers to output: log only triggering buffers
Updated by Andreas Herz over 7 years ago
- Assignee set to OISF Dev
- Target version set to TBD
Actions