nfr
nfr copied to clipboard
Send "service" column from zeek logs
Zeek IP logs (conn.log) contain "service" column with application protocol, if detected. We can find values like "dns" or "ssl" in there. We should send it upstream as an "app" field.