Closed GoogleCodeExporter closed 9 years ago
[deleted comment]
The problem starts after r862, which adds the following line to syslog-ng.conf:
db-parser(file("/etc/elsa_local_patterndb.xml"));
With that line enabled, suricata alerts are given class=NONE. Commenting out
that line restores order.
Original comment by kebut...@gmail.com
on 8 May 2013 at 2:50
That's too bad, I guess it won't work to have dual patterndb files, though my
initial testing seemed to suggest otherwise. I've backed out that change so
this should work again.
Original comment by mchol...@gmail.com
on 8 May 2013 at 3:03
Original issue reported on code.google.com by
br...@hurrikane.net
on 7 May 2013 at 8:26