You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Closing as "unplanned." The only way to do this with zeek will be to run multiple separate zeek clusters on each node, one for each capture interface, which is going to introduce a complexity to the sensors I don't think would be worth the issues that might arise from it. Not to mention the arkime and suricata sides. I understand the reasoning for the feature, it's just not feasible with the tools we're using.
this document describes how tags can be configured for a hedgehog sensor.
A request came in from a Malcolm user to allow tags to be specified per-capture interface.
The text was updated successfully, but these errors were encountered: