From af615baaf700506476a168d57d26f1367c4907d4 Mon Sep 17 00:00:00 2001 From: Jeff Lucovsky Date: Sat, 28 Sep 2019 08:57:29 -0400 Subject: [PATCH] logging/alert: Expand alert logging description Clarify the configuration requirements for alerts and http-body logging. --- suricata.yaml.in | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/suricata.yaml.in b/suricata.yaml.in index 20e512b1be..c9852c010e 100644 --- a/suricata.yaml.in +++ b/suricata.yaml.in @@ -148,9 +148,9 @@ outputs: # payload-buffer-size: 4kb # max size of payload buffer to output in eve-log # payload-printable: yes # enable dumping payload in printable (lossy) format # packet: yes # enable dumping of packet (without stream segments) - # http-body: yes # enable dumping of http body in Base64 - # http-body-printable: yes # enable dumping of http body in printable format # metadata: no # enable inclusion of app layer metadata with alert. Default yes + # http-body: yes # Requires metadata; enable dumping of http body in Base64 + # http-body-printable: yes # Requires metadata; enable dumping of http body in printable format # Enable the logging of tagged packets for rules using the # "tag" keyword.