Actions
Feature #1830
closedsupport 'tag' in eve log
Description
When using the tag keyword special tag records are being written out to unified2. This way more packets than just the one triggering the alert are logged.
Eve should support the same thing. Probably through the 'alert' record with a special sid/gid like in unified2.
Updated by Victor Julien over 8 years ago
- Status changed from Assigned to Closed
- Target version changed from 70 to 3.1.2
Actions