Open mmguero opened 3 months ago
It may be useful in some cases to have community ID as part of more zeek logs than conn.log. This would be a configurable option.
However, (at least as of 2020) there isn't a generalized mechanism to add a field to ALL logs. See corelight/zeek-community-id#3.
This gives us a few options, if we wanted to do this:
It may be useful in some cases to have community ID as part of more zeek logs than conn.log. This would be a configurable option.
However, (at least as of 2020) there isn't a generalized mechanism to add a field to ALL logs. See corelight/zeek-community-id#3.
This gives us a few options, if we wanted to do this: