Closed ngms17 closed 1 year ago
How are you adding events to your database?
I have the same question. I am using Suricata and ELK. NO Filebeat
Hi am sending the logs to ES via Filebeat (Suricata module) and i am running evebox server against my ES host to fetch the events
GeoIP data should be added by the log processor. So in these cases either Logstash or Filebeat.
If the geoip is being added, but just not being displayed by EveBox, send me an event sample in JSON and I'll take a look.
How can i send it to you on private?
I'm talking about this panel in evebox. How to make it work? Screenshot is from working stamus selks.
GeoIP in Logstash works fine, thanks for your reply
How can i send it to you on private?
My email should be visible on my GitHub profile if you want to verify, but email to ish@unx.ca works.
Any news?
Any news?
Not really. I have ECS events now in my Elastic and see the geo ip.. Won't be hard to add now. Next week or 2 as I'm travelling this week.
Looking at something like this for ECS provided GeoIP...
Thank you! Seems perfect. Waiting for any updates
You can give the latest development build a try: https://evebox.org/files/development/
How can i get evebox to show me the GeoIP section when i look into a event/alert log?
I already have the geoIP databases on my server.
Thank you.