Hi,
I am seeing another major change in the json structure. In anomaly we have:
community_id metadata.flowbits anomaly events.
cat eve.json | jq 'select(.anomaly)|.flow_id,.anomaly’
On other occasions, it appears differently:
Best Regads,