mirror of https://github.com/OISF/suricata
eve: add rule generation source to alert record
When an alert is generated from firewall context, add an engine value of
"fw", otherwise "td" (for threat detect).
The engine field is only added when firewall mode is enabled.
Ticket: #8456
(cherry picked from commit 029fd1be59)
pull/15385/head
parent
69e829b082
commit
1a09a059dc
Loading…
Reference in New Issue