Project

General

Profile

Actions

Task #6084

closed

output/alert: enable logging `PASS` alerts

Added by Juliana Fajardini Reichow over 1 year ago. Updated 4 months ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Target version:
-
Effort:
Difficulty:
Label:

Description

This should be part of the `alert` event, but allowing to log `pass` rules that triggered.

Will likely involve work related to the alerts queue.


Related issues 1 (0 open1 closed)

Related to Suricata - Bug #5464: eve: if alert and drop rules match for a packet, "alert.action" is ambigiousClosedJuliana Fajardini ReichowActions
Actions

Also available in: Atom PDF