unified2 alerts not including xff ips using extra-data mode
Tested on Suricata 4.0.1
For an HTTP request with XFF headers, unified2 alert output does not include extra data events with XFF info.
Enabled XFF with extra-data mode configuration per: https://redmine.openinfosecfoundation.org/projects/suricata/repository/revisions/master/entry/suricata.yaml.in#L280
Full configuration file also attached.
Attached rules file is intended to trigger alerts for each packet.
Tested pcap and unified2 output also attached.
Note: Using overwrite mode worked as expected, only extra-data mode has this issue.