# Include the 'short name' from classification.config in the all-eve.log

**URL:** <https://forum.suricata.io/t/include-the-short-name-from-classification-config-in-the-all-eve-log/350>\
**Category:** Help\
**Created:** [June 19, 2020, 2:33pm UTC](https://forum.suricata.io/t/include-the-short-name-from-classification-config-in-the-all-eve-log/350 "2020-06-19T14:33:27Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![scott\_ca](https://avatars.discourse-cdn.com/v4/letter/s/94ad74/32.png) [@scott\_ca](https://forum.suricata.io/u/scott_ca)\
**Post date:** [June 19, 2020, 2:33pm UTC](https://forum.suricata.io/t/include-the-short-name-from-classification-config-in-the-all-eve-log/350/1 "2020-06-19T14:33:27Z")

</div>

Hello. Is there a way to have suricata include the ‘short name’ of a classtype (from classification.config) in the all-eve.log? Suricata includes the classification description but not the ‘short name’.

For example, `config classification: successful-admin,Successful Administrator Privilege Gain,1` I’d like to include _successful-admin_

Thanks.

---

<div class="post-metadata">

**Author:** ![greemi01](https://avatars.discourse-cdn.com/v4/letter/g/3be4f8/32.png) [@greemi01](https://forum.suricata.io/u/greemi01)\
**Post date:** [February 16, 2021, 10:39pm UTC](https://forum.suricata.io/t/include-the-short-name-from-classification-config-in-the-all-eve-log/350/2 "2021-02-16T22:39:17Z")

</div>

Hi, Did you find a solution to this ? I’d like to do the same thing.

---

<div class="post-metadata">

**Author:** ![vjulien](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/vjulien/32/4_2.png) [@vjulien](https://forum.suricata.io/u/vjulien)\
**Post date:** [February 17, 2021, 7:24am UTC](https://forum.suricata.io/t/include-the-short-name-from-classification-config-in-the-all-eve-log/350/3 "2021-02-17T07:24:13Z")

</div>

Overlooked this back in June. There is no way to do this currently, but it probably wouldn’t be hard. Feel free to open a feature ticket for it.

---

<div class="post-metadata">

**Author:** ![greemi01](https://avatars.discourse-cdn.com/v4/letter/g/3be4f8/32.png) [@greemi01](https://forum.suricata.io/u/greemi01)\
**Post date:** [February 17, 2021, 11:39am UTC](https://forum.suricata.io/t/include-the-short-name-from-classification-config-in-the-all-eve-log/350/4 "2021-02-17T11:39:39Z")

</div>

Hi,

Thanks. I hate to ask such a ‘stupid’ question … but it is not obvious to me where to submit a feature ticket.

Thanks,

Michael

---

<div class="post-metadata">

**Author:** ![sbhardwaj](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/sbhardwaj/32/10_2.png) [@sbhardwaj](https://forum.suricata.io/u/sbhardwaj)\
**Post date:** [February 17, 2021, 2:30pm UTC](https://forum.suricata.io/t/include-the-short-name-from-classification-config-in-the-all-eve-log/350/5 "2021-02-17T14:30:37Z")

</div>

Its not a stupid question. Its perfectly alright to ask. 🙂  
Please do so on [https://redmine.openinfosecfoundation.org](https://redmine.openinfosecfoundation.org)

---

<div class="post-metadata">

**Author:** ![scott\_ca](https://avatars.discourse-cdn.com/v4/letter/s/94ad74/32.png) [@scott\_ca](https://forum.suricata.io/u/scott_ca)\
**Post date:** [February 17, 2021, 3:10pm UTC](https://forum.suricata.io/t/include-the-short-name-from-classification-config-in-the-all-eve-log/350/6 "2021-02-17T15:10:01Z")

</div>

Thanks, Victor and Shivani. I ended up using the classification description for our needs, but I will definitely submit a feature request for this, too.

---

<div class="post-metadata">

**Author:** ![scott\_ca](https://avatars.discourse-cdn.com/v4/letter/s/94ad74/32.png) [@scott\_ca](https://forum.suricata.io/u/scott_ca)\
**Post date:** [June 21, 2024, 3:29pm UTC](https://forum.suricata.io/t/include-the-short-name-from-classification-config-in-the-all-eve-log/350/7 "2024-06-21T15:29:46Z")

</div>

Seems there is a bit of recent movement on a feature request I made:

> **[Feature #4333: Include the ‘short name’ from classification.config in the...](https://redmine.openinfosecfoundation.org/issues/4333#change-34976)**
>
> Redmine

Thanks, everyone
