brimdata / build-suricata

Build Suricata for packaging with Brim
8 stars 2 forks source link

Community ID not populated on Windows #43

Closed philrz closed 4 years ago

philrz commented 4 years ago

Testing with artifact Brim-Setup-rc-v0.20.0-suricata18.exe on Windows, we see Suricata alerts are being generated, but the community_id field is consistently null. I think we already knew this, but I hadn't yet opened an official issue to track it.

image

philrz commented 4 years ago

Verified in the Brim-Setup-rc-v0.20.0-suricata20.exe test release candidate, which is based on Brim commit 0481863. I can now see the Community ID fields being populated on Windows where we did not before.

image

Thanks @henridf!