Actions
Bug #7569
closedlogging: Mac addresses are not logged for pkt_src detect/log or flow timeout
Affected Versions:
Effort:
Difficulty:
Label:
Description
Cf https://forum.suricata.io/t/some-mac-addresses-are-missing-in-the-http-logs/5389/2
Not sure if we will want to backport this
Check with jq 'select(.ether == null)' log/eve.json
and having ethernet: yes
in suricata.yaml
Actions