Question
Question 1
cat /var/log/suricata/old_eve.json | jq -c 'select(.event_type == "http")' | head -1 | jq .
Question 2


Last updated
cat /var/log/suricata/old_eve.json | jq -c 'select(.event_type == "http")' | head -1 | jq .


Last updated
vim /etc/suricata/suricata.yamlsuricata -r /home/htb-student/pcaps/suspicious.pcap -k none -l .