Actions
Feature #1007
closedunited output
Effort:
Difficulty:
Label:
Description
Unified output for all events and alerts into a single "stream", where the stream can be a file, socket, etc.
Files
Actions
Added by Victor Julien about 12 years ago. Updated almost 12 years ago.
Description
Unified output for all events and alerts into a single "stream", where the stream can be a file, socket, etc.
Files
| enhanced-alerting.rst (2.83 KB) enhanced-alerting.rst | RFC sent to ML | Eric Leblond, 10/25/2013 05:56 AM |
The logging format can be JSON. It should contains all the information available and be extensible:
Attached file is proposal.
Merged through https://github.com/inliniac/suricata/pull/807