Hello. Is there a way to have suricata include the ‘short name’ of a classtype (from classification.config) in the all-eve.log? Suricata includes the classification description but not the ‘short name’.
For example, config classification: successful-admin,Successful Administrator Privilege Gain,1 I’d like to include successful-admin
Thanks, Victor and Shivani. I ended up using the classification description for our needs, but I will definitely submit a feature request for this, too.