Malcolm and Suricata alert IP association issue #660
Unanswered
H-Dynamite
asked this question in
Q&A
Replies: 1 comment
-
I'm not quite sure I understand the issue you're describing. If you'd like to examine the |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Some of the suricata events collected by Malcolm have issues where the source IP and destination IP are opposite. I feel that the events should be associated with the IP field of the suricata flow
Beta Was this translation helpful? Give feedback.
All reactions