Skip to content

ipworkx/ecs-suricata

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

14 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

ecs-suricata

Because the version of Rob Cowart was outdated and Elastic itself wasn't doing kafka in between, I modded it al together.

This is the first version of a suricata with kibana 7.6.0 using ECS compliant scheme. It is compatible with SIEM.

As input source I used kafka. All sensors push raw surciata json data into a kafka topic. To do this job I used beats

A example filebeat.yml is included

Main Screen

Main Screen

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages