Closed peasead closed 4 years ago
Process to test:
logstash-601-filter-suricata-alert.conf
file to /etc/logstash/conf.d/
, restart Logstashimport-saved-objects.sh
shell script in the ecs-configuration/Kibana
directory on a sensorecs-*
and ecs-Suricata-*
indices
Added a Logstash Suricata alert configuration to populate the Elastic SIEM.
Updated the Suricata dashboards to work with the new Suricata Logstash configuration.
Tested with