evebox
evebox copied to clipboard
view SID Reference in eve.json
how to add field Reference & link SID in .json field ?
for view in eve-box and send to SIEM .
Sample References Url: doc.emergingthreats.net/2001583
thanks for support ! Best Regard .
This might be something I added to the user interface in EveBox. Adding it directly to the event record for having available in other SIEMs would be the job of Suricata, not EveBox. While it can't do this yet, it may be added to Suricata soon.
Clonse in favour of https://github.com/jasonish/evebox/issues/296.