I send the data of the fast.log in a SIEM.
How can I get the contents of the line that triggered the alert from the eve.json file in the fast.log file ?
I have looked in the suricata.yaml file but I cannot get it to work. Do you have an example with which lines to uncomment?