Skip to content

Instantly share code, notes, and snippets.

@jasonish
Created October 23, 2020 22:12
Show Gist options
  • Select an option

  • Save jasonish/b678ee429d285004525b318d04ec71ea to your computer and use it in GitHub Desktop.

Select an option

Save jasonish/b678ee429d285004525b318d04ec71ea to your computer and use it in GitHub Desktop.
Suricata: Log file hashes without file extraction
outputs:
- eve-log:
enabled: yes
types:
- files
- alert
- file-store:
version: 2
enabled: yes
force-filestore: no
stream-depth: 0
force-hash: [md5, sha1, sha256]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment