Actions
Feature #6457
openeve: configurable list of fields in output
Description
Suricata should be able to get a schema.json as input :
This schema.json has a reduced number of fields compared to what Suricata can output.
The fields that are absent should not be output by Suricata (for instance we could have everything but dnp3.application.objects
)
Updated by Philippe Antoine 12 months ago
- Related to Task #6443: Suricon 2023 brainstorm added
Updated by Victor Julien 12 months ago
- Tracker changed from Optimization to Feature
- Subject changed from Configurable list of fields in output to eve: configurable list of fields in output
Actions