Actions
Feature #4179
opentunnel-Node for flow, netflow and dns-events in eve.json
Effort:
Difficulty:
Label:
Needs Suricata-Verify test
Description
For suricata alert-events in eve.json there is a tunnel-node, that contains the outer ip-addresses. It would be great to get this node for flow-, netflow- and dns-events as well. This would make it possible to clearly identify the flow and compare/merge it with results of other tools.
Updated by Philippe Antoine 6 months ago
- Assignee set to Community Ticket
- Target version set to TBD
- Label Needs Suricata-Verify test added
Would you have a pcap to show this ?
Actions