Allow log for payload and packet only for defined sid
Suricata config file having a feature for logging for all payload and packet, but does not have a feature for only defined sids.
- payload: yes # enable dumping payload in Base64
- payload-buffer-size: 4kb # max size of payload buffer to output in eve-log
- payload-printable: yes # enable dumping payload in printable (lossy) format
- packet: yes # enable dumping of packet (without stream segments)
Can we have a feature logging payload and packet only defined sids?