add community ID to more (all) Zeek logs types #444
Labels
enhancement
New feature or request
external
Depends on a bug or feature external to this project
zeek
Relating to Malcolm's use of Zeek
Milestone
It may be useful in some cases to have community ID as part of more zeek logs than conn.log. This would be a configurable option.
However, (at least as of 2020) there isn't a generalized mechanism to add a field to ALL logs. See corelight/zeek-community-id#3.
This gives us a few options, if we wanted to do this:
The text was updated successfully, but these errors were encountered: