intrusion detection: log drops and alerts causing them

This commit is contained in:
Franco Fichtner 2018-01-20 12:17:04 +01:00
parent 5e970ddf87
commit 573612d48e

View File

@ -117,7 +117,10 @@ outputs:
# - files:
# force-magic: no # force logging magic on all logged files
# force-md5: no # force logging of md5 checksums
# #- drop
- drop:
alerts: yes # log alerts that caused drops
flows: start # start or all: 'start' logs only a single drop
# per flow direction. All logs each dropped pkt.
# - ssh
# alert output for use with Barnyard2