Skip to content

Instantly share code, notes, and snippets.

@jasonish
Created March 5, 2018 22:30
Show Gist options
  • Save jasonish/94ee9c8b51edb2451147fceb47d42536 to your computer and use it in GitHub Desktop.
Save jasonish/94ee9c8b51edb2451147fceb47d42536 to your computer and use it in GitHub Desktop.
%YAML 1.1
---
outputs:
- eve-log:
enabled: yes
filetype: redis
filename: eve.json
redis:
server: 127.0.0.1
port: 6379
async: true
mode: list
types:
- alert:
metadata: yes
tagged-packets: yes
xff:
enabled: no
mode: extra-data
deployment: reverse
header: X-Forwarded-For
- http:
extended: yes # enable this for extended logging information
- dns:
query: yes # enable logging of DNS queries
answer: yes # enable logging of DNS answers
- tls:
extended: yes # enable this for extended logging information
- files:
force-magic: no # force logging magic on all logged files
- smtp:
- ssh
- stats:
totals: yes # stats for all threads merged together
threads: no # per thread stats
deltas: no # include delta values
- flow
- eve-log:
enabled: yes
filetype: regular
filename: eve.json
types:
- alert:
metadata: yes
tagged-packets: yes
xff:
enabled: no
mode: extra-data
deployment: reverse
header: X-Forwarded-For
- http:
extended: yes # enable this for extended logging information
- dns:
query: yes # enable logging of DNS queries
answer: yes # enable logging of DNS answers
- tls:
extended: yes # enable this for extended logging information
- files:
force-magic: no # force logging magic on all logged files
- smtp:
- ssh
- stats:
totals: yes # stats for all threads merged together
threads: no # per thread stats
deltas: no # include delta values
- flow
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment