Project

General

Profile

Actions

Feature #772

closed

Feature #1007: united output

JSON output for alerts

Added by Aaron Nikula about 11 years ago. Updated about 10 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

I think it would be beneficial for Suricata to have an optional JSON formatted log file for alerts.

Some background: Right now the popular frontends that work with Suricata are dependent on Unified2 and Barnyard2 to get data from Suricata into a database. With JSON, there is more log file overhead but then this data can be more easily managed/forwarded with tools like syslog-ng, and then imported to MySQL or a non-traditional database like MongoDB.


Subtasks 1 (0 open1 closed)

Feature #542: TLS JSON outputClosedTom DeCanio09/06/2012Actions
Actions

Also available in: Atom PDF