<description>Record events for rule matches</description>
</valueHelp>
<valueHelp>
<format>anomaly</format>
<description>Record unexpected conditions such as truncated packets, packets with invalid IP/UDP/TCP length values, and other events that render the packet invalid for further processing or describe unexpected behavior on an established stream</description>
</valueHelp>
<valueHelp>
<format>drop</format>
<description>Record events for dropped packets</description>
</valueHelp>
<valueHelp>
<format>file</format>
<description>Record file details (e.g., MD5) for files extracted from application protocols (e.g., HTTP)</description>