Actions
Feature #4974
closedLog references to Eve
Effort:
Difficulty:
Label:
Description
Its been discussed a few time of references should be logged to eve. This would give alerts more context without access to the rule. However, logging the rule is also an option.
The reference logged should probably be the fully expanded reference.
Updated by Philippe Antoine almost 3 years ago
See https://github.com/OISF/suricata/pull/6677 : Remove unused (for now) references
from signature
Updated by Jeff Lucovsky 8 months ago
- Status changed from New to In Review
- Assignee changed from OISF Dev to Jeff Lucovsky
Updated by Juliana Fajardini Reichow 8 months ago
- Target version changed from TBD to 8.0.0-beta1
Updated by Jeff Lucovsky 3 months ago
- Status changed from In Review to Closed
Actions