mirror of https://github.com/OISF/suricata
output-json: add app_proto key in root
By adding the key in the root of *flow and fileinfo events it
will be possible to get all events for one application layer by
using a 'event_type:proto OR app_proto:proto' filter. This will
permit to the analyst to get a good view of events related to
one protocol.
This patch also fixes a regression in file logging where app_proto
was available before 94dbd303e4 create
the regression.
pull/1784/head
parent
8ac48872a5
commit
538f37bd38
Loading…
Reference in New Issue