Actions
Support #2578
closedHow to distinguish the alert
Status:
Closed
Priority:
Normal
Assignee:
-
Affected Versions:
Label:
Description
Hi guys,I want to analyze multiple pcap files with suricata. How should I distinguish which pcap file the alert belongs to?
Updated by Victor Julien over 6 years ago
Simplest way is to specify different output directories (-l <dir> command line). In 4.1 there will be an optional 'pcap_file' field in the eve log.
Actions