Add information about last filter match to reporter
It would be very useful to have information about last filter match timestamp. This information could be used to prune the list of all defined filters and remove those that are not matching anymore and just delay the processing.
Updated by Pavel Kácha 8 months ago
Maybe we could start (or complement that) with more verbose logging? Now it seems we log just number of events:
Filters let 1 events through, 0 blocked.
If we logged names of matching rules, we could do even more interesting awk-jobs (like “how many events from this particular detector gets dropped”, or “how many people drop something concerning this detector”)