Actions
Feature #3701
closed
JO
JO
eve: add tenant_id in eve-log for other types than alert
Feature #3701:
eve: add tenant_id in eve-log for other types than alert
Effort:
Difficulty:
Label:
Description
We're in the process of adopting multi-tenant support in Suricata and we've run in to the issue that the tenant_id is only being logged for alert type logging. But we also process other event types, which will also have to be sorted according to respective tenants.
Actions