mirror of https://github.com/OISF/suricata
eve: add rule generation source to alert record
When an alert is generated from firewall context, add an engine value of "fw", otherwise "td" (for threat detect). The engine field is only added when firewall mode is enabled. Ticket: #8456pull/15370/head
parent
f0e246de34
commit
029fd1be59
Loading…
Reference in New Issue