Hi,
In tests with GeoIP that use libmaxminddb, when using the geoip settings in the rule according to 7.3. IP Keywords — Suricata 6.0.13 documentation blocking can be done using a geoip-database, so far so good.
I would like all logs to report the geolocation of all traffic, regardless of the action (alert, outage,…). Is there any variable in geoip that can be used to inform the country’s iso_code in all logs?
Suricata version: 6.0.13 compiled
OS: Debian