Project

General

Profile

Actions

Feature #3701

closed

eve: add tenant_id in eve-log for other types than alert

Added by Justin Ossevoort almost 4 years ago. Updated over 3 years ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

We're in the process of adopting multi-tenant support in Suricata and we've run in to the issue that the tenant_id is only being logged for alert type logging. But we also process other event types, which will also have to be sorted according to respective tenants.

Actions

Also available in: Atom PDF