-
Notifications
You must be signed in to change notification settings - Fork 15
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Question About logstash #4
Comments
You can use logstash or filebeat. |
Hi Alex, Check the following logstash.conf as an example (you might need to fix some filters. Haven't tested that conf lately): It reads suricata logs at the default folder: |
Thank you rcfontana. I was looking exactly for https://github.com/StamusNetworks/SELKS/blob/master/staging/etc/logstash/conf.d/logstash.conf |
Thanks @rcfontana ! |
Hello,
I'm newbie on ELK but I dont have clear how I can transmit suricata logs to elasticsearch.
Do you use logstash? any other way?
Thank you
The text was updated successfully, but these errors were encountered: