Loading

Suricata Integration

Stack 9.0.0 Serverless Observability Serverless Security

Version 2.25.1 (View all)
Subscription level
What's this?
Basic
Level of support
What's this?
Elastic
Ingestion method(s) File

This integration is for Suricata. It reads the EVE JSON output file. The EVE output writes alerts, anomalies, metadata, file info and protocol specific records as JSON.

This module has been developed against Suricata v4.0.4, but is expected to work with other versions of Suricata.

This integration includes one or more Kibana dashboards that visualizes the data collected by the integration. The screenshots below illustrate how the ingested data is displayed.