Skip to content

Latest commit

 

History

History
50 lines (32 loc) · 1.1 KB

suricata.asciidoc

File metadata and controls

50 lines (32 loc) · 1.1 KB

Suricata module

This is a module to the Suricata IDS/IPS/NSM log. It parses logs that are in the Suricata Eve JSON format.

Compatibility

This module requires the {plugins}/ingest-geoip.html[ingest-geoip] and {plugins}/ingest-user-agent.html[ingest-user-agent] Elasticsearch plugins.

This module has been developed against Suricata v4.0.4, but is expected to work with other versions of Suricata.

Example dashboard

This module comes with a sample dashboard. For example:

kibana suricata

TODO: provide an example configuration

eve log fileset settings