I know that report in suricata like fast.log can be customized using lua script (fast.lua) but is it possible to use bash script to have the similar custom report like fast.sh? I’m more familar with bash scripting.
Thanks for the suggestion. Can we make the eve output only display alert log like fast.log? There are a bunch of JSON data in eve output even if alert is not triggered. I think this can be customized in suricata.yaml, but there are too many of them. Can anyone show me this config that will make eve.json output the similar thing from fast.log ?