I'm using this filter to enhance reporting for suricata alerts, and I've recently discovered that when a blank result is returned, it appears to stop processing that particular event. Not sure if this is intended behavior, but if so, it could be beneficial to have a boolean that would allow the output variables to be set to, say, blank_result_returned when this happens.
I'm using this filter to enhance reporting for suricata alerts, and I've recently discovered that when a blank result is returned, it appears to stop processing that particular event. Not sure if this is intended behavior, but if so, it could be beneficial to have a boolean that would allow the output variables to be set to, say, blank_result_returned when this happens.