cscli collections install crowdsecurity/suricatacscli collections install crowdsecurity/whitelist-good-actorscscli parsers install crowdsecurity/whitelists
---filenames: - /var/log/suricata/fast.loglabels: type: suricata-fastlogs---
# logfilename [owner:group] mode count size when flags [/pid_file] [sig_num]/var/log/suricata/fast.log root:wheel 640 3 * $D0 BZ /var/run/suricata.pid 1
%YAML 1.1---# empty stub for custom modifications, add custom persistent config below# Configure the type of alert (and other) logging you would like.outputs: # a line based alerts log similar to Snort's fast.log - fast: enabled: yes filename: fast.log append: yes #filetype: regular # 'regular', 'unix_stream' or 'unix_dgram' # Extensible Event Format (nicknamed EVE) event log in JSON format - eve-log: enabled: yes...