Closed jdeluyck closed 11 months ago
The Suricata event is nested under the event
field here, so it will need some conversion like:
cat input.json | jq -c .event > fixed.json
The Suricata event is nested under the
event
field here, so it will need some conversion like:cat input.json | jq -c .event > fixed.json
Thank you! I'm fairly new to EVE logging, so I hadn't noticed that...
I've been trying to use evebox on the netflow logs from AWS Network Firewall, which uses Suricata under the hood.
The error I get back is
Small file which should work but doesn't