I originally sent this to the wrong email address – sorry Bro team.
I used this script:
https://gist.github.com/J-Gras/f9f86828f9e9d9c0b8f0908bc3573bb0
to log simultaneously as JSON and normal Bro TSV.
I’m seeing only a fraction of the total logs being written as JSON – it varies between about 25-40%.
The script looks OK to me. Any ideas what’s wrong? Is there a better way to do dual log streams?
Thanks,
Jay