There are three configuration options to the configuration parameter 'event_queue'.
This determines the maximum size of the event queue. For example, if the event queue has a max size of 8, only 8 events will be stored for a single packet or stream.
The default value is 8.
This determines the number of events to log for a given packet or stream. You can't log more than the max_event number that was specified.
The default value is 3.
This argument determines the way that the incoming events are ordered. We currently have two different methods:
The method in which events are ordered does not affect rule types such as pass, alert, log, etc.
The default value is content_length.