[Oisf-users] eve.log and event types

Vieri rentorbuy at yahoo.com
Thu Dec 29 07:50:41 UTC 2016


________________________________
> From: Jason Ish <lists at unx.ca>

> Yes, you're going to have to edit the yaml. The set doesn't play nicely with lists, it might be 

> possible if these had "enabled" flags, but they don't. Their existence in the list enables them.

Too bad.

> Another option is to create a new YAML that includes the default, then re-define the outputs section.


Not bad.
I think I'll use this solution.

Thanks,

Vieri



More information about the Oisf-users mailing list