Prelude output IDMEF message issue
The Prelude Siem output (IDMEF) of Suricata might be confused from version 4.1.2. The alert.classification.text field which should contain the signature name (for example ET Policy...) swapped with alert.assessment.impact.description(classification for example Corporate policy violation). In other words after version 4.1.2 we see the classification instead of the signature name and in the description we could see the signature name where was previously the classification.
Could you please check it?