-
-
Save jasonish/71e56a62f4380ae6a389f5c414570879 to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
%YAML 1.1 | |
--- | |
outputs: | |
- eve-log: | |
enabled: yes | |
filetype: redis | |
filename: eve.json | |
redis: | |
server: 127.0.0.1 | |
port: 6379 | |
async: true | |
mode: list | |
types: | |
- alert: | |
metadata: yes | |
tagged-packets: yes | |
xff: | |
enabled: no | |
mode: extra-data | |
deployment: reverse | |
header: X-Forwarded-For | |
- http: | |
extended: yes # enable this for extended logging information | |
- dns: | |
query: yes # enable logging of DNS queries | |
answer: yes # enable logging of DNS answers | |
- tls: | |
extended: yes # enable this for extended logging information | |
- files: | |
force-magic: no # force logging magic on all logged files | |
- smtp: | |
- ssh | |
- stats: | |
totals: yes # stats for all threads merged together | |
threads: no # per thread stats | |
deltas: no # include delta values | |
- flow | |
- eve-log: | |
enabled: yes | |
filetype: regular | |
filename: eve.json | |
types: | |
- alert: | |
metadata: yes | |
tagged-packets: yes | |
xff: | |
enabled: no | |
mode: extra-data | |
deployment: reverse | |
header: X-Forwarded-For | |
- http: | |
extended: yes # enable this for extended logging information | |
- dns: | |
query: yes # enable logging of DNS queries | |
answer: yes # enable logging of DNS answers | |
- tls: | |
extended: yes # enable this for extended logging information | |
- files: | |
force-magic: no # force logging magic on all logged files | |
- smtp: | |
- ssh | |
- stats: | |
totals: yes # stats for all threads merged together | |
threads: no # per thread stats | |
deltas: no # include delta values | |
- flow |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment