add ability to generate suricata.yaml such that suricata's eve.json is split/rotated so it doesn't grow as large #445
Labels
enhancement
New feature or request
performance
Related to speed/performance
suricata
Relating to Malcolm's use of Suricata
Milestone
We need to look at adding to suricata_config_populate.py the ability to generate suricata.yaml such that suricata's eve.json is split/rotated so it doesn't grow as large.
There are a few things we could do here as possibilities
rotate-interval: hour
)types
in the example below)The text was updated successfully, but these errors were encountered: