--- /dev/null
+%YAML 1.1
+---
+
+outputs:
+ - eve-log:
+ enabled: yes
+ filetype: regular #regular|syslog|unix_dgram|unix_stream|redis
+ filename: eve.json
+ ethernet: true
+ metadata: true
+ community-id: true
+ community-id-seed: 1234
+ types:
+ - alert:
+ payload: yes # enable dumping payload in Base64
+ payload-buffer-size: 4kb # max size of payload buffer to output in eve-log
+ payload-printable: yes # enable dumping payload in printable (lossy) format
+ packet: yes # enable dumping of packet (without stream segments)
+ metadata: yes # enable inclusion of app layer metadata with alert. Default yes
+ tagged-packets: yes
+ - anomaly:
+ enabled: yes
+ types:
+ decode: yes
+ stream: yes
+ applayer: yes
+ packethdr: yes
+ - files:
+ force-magic: yes
+ force-hash: [md5, sha1, sha256]
+ - nfs
+ - flow
+ - netflow
+ - alert-debug:
+ enabled: yes
+ filename: alert-debug.log
+ append: yes
+ #filetype: regular # 'regular', 'unix_stream' or 'unix_dgram'
+
+app-layer:
+ protocols:
+ nfs:
+ udp:
+ enabled: yes
+ tcp:
+ enabled: no