不多说,直接上干货!
见官网
https://suricata.readthedocs.io/en/latest/output/index.html
总的来说,Suricata采集下来的数据输出分为:EVE 、 Lua Output 、 Syslog Alerting Compatibility 、 Custom http logging 、 Custom tls logging 和 Log Rotation
12.1. EVE
12.1.1. Eve JSON Output
12.1.2. Eve JSON Format
12.1.2.1. Common Section
12.1.2.2. Event type: Alert
12.1.2.3. Event type: HTTP
12.1.2.4. Event type: DNS
12.1.2.5. Event type: TLS
12.1.3. Eve JSON ‘jq’ Examples
12.2. Lua Output
12.3. Syslog Alerting Compatibility
12.4. Custom http logging
12.5. Custom tls logging
12.6. Log Rotation
手机扫一扫
移动阅读更方便
你可能感兴趣的文章