Skip to content

Instantly share code, notes, and snippets.

@jasonish
Forked from victorjulien/idea.yaml
Last active January 29, 2018 22:41
Show Gist options
  • Save jasonish/10d1d4dc2b6d631cd13cd828e953d6bd to your computer and use it in GitHub Desktop.
Save jasonish/10d1d4dc2b6d631cd13cd828e953d6bd to your computer and use it in GitHub Desktop.
outputs:
- eve-log:
types:
- alert:
metadata: yes
# Include context from the rule that triggered the alert.
# Defaults:
# - raw: false
# - metadata: true
# - references: false
rule:
raw: false
metadata: true
references: false
# This would log references and metadata, as metadata is true by default.
rule:
references: true
# This would only log the raw rule.
rule:
raw: true
metadata: false
outputs:
- eve-log:
types:
- alert:
extra-data:
app-layer: true
flow: true
rule:
raw: false
metadata: true
references: false
outputs:
- eve-log:
types:
- alert:
metadata:
app-layer: true
flow: true
rule:
raw: false
metadata: true
references: false
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment