Installing Suricata and Filebeat on Centos and Shipping Suricata Logs to Elastic SIEM

preview_player
Показать описание
Suricata is one such NIDS solution, which is open source and can be quickly deployed either on dedicated hardware for monitoring one or more transit points on your network, or directly on existing Unix-like hosts to monitor just their own network traffic. Because Suricata is capable of generating JSON logs of NIDS events, it integrates beautifully with Elastic SIEM.
Рекомендации по теме
Комментарии
Автор

The branchnetconsulting-page which you got your suricata.yaml-content from isn't accessible anymore and since you don't show the configuration afterwards, it's become hard or impossible to follow your tutorial 😕

Could you share the yaml-content somewhere so we can access it again?

commentor
Автор

Could you help me please ? I have problem when I execute sudo filebeat setup I was error like this : Loading dashboards (Kibana must be running and reachable)
Exiting: error connecting to Kibana: fail to get the Kibana version

wardaamalou
Автор

Could you tell me from where you copy the hosts in elastic output

shailendraverma