It would be really nice if there were a way to tell suricata to use ISO 8601 timestamps everywhere instead of sometimes using ISO and sometimes using something else. (This would be feature #1469 which seems to have languished without comment for 2 years.)