Actions
Feature #8479
open
VJ
eve/firewall: dedicated log record type
Feature #8479:
eve/firewall: dedicated log record type
Effort:
Difficulty:
Label:
Description
Currently the firewall mode rules are not logging by default, but can use the alert keyword to generate an alert when they match. This produces the rich alert record type.
It may be worth considering a more dedicated type, that includes the drop record type info as well as detailed info about states, etc.
Actions