Retrieve metadata only related to alerts

Hello everyone,
I’m looking for a simple and effective way to configure Suricata to retrieve only metadata related to alerts.
Does put the parameter
metadata:yes
in the type alert config lines of the - eve-log: section
can be enough?

Thank you in advance for your help.

Hi! Welcome to our forum! :slight_smile:

Seems like eve-log.types.alert.metadata is set to yes by default. Have you tried checking your alerts for any metadata?
Let us know if you’re looking for something specific in the alert metadata.