Skip to content

Instantly share code, notes, and snippets.

@jasonish
Last active January 29, 2018 22:23
Show Gist options
  • Save jasonish/8fafa9904689ca26472af227c2ef78fa to your computer and use it in GitHub Desktop.
Save jasonish/8fafa9904689ca26472af227c2ef78fa to your computer and use it in GitHub Desktop.
outputs:
- eve-log:
types:
- alert:
metadata: yes
rule-metadata:
enabled: yes
rule: yes
outputs:
- eve-log:
types:
- alert:
include:
- app-layer
- rule
- rule.metadata
- payload
- http-body
@regit
Copy link

regit commented Jan 29, 2018

outputs:
  - eve-log:
      types:
        - alert:
            context: yes
            rule:
              - metadata: yes
              - signature: yes

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment