Hello, i’m using elk with suricata.
I want to understand how suricata is working. My problem is that i got logs with filebeat that are shown in my elastic (kibana) but no alert OwO…
I can provide my suricata.yaml and all other things u need to explain to me how all is working.
First is to check if Suricata is actually alerting or not. This is best done by looking at the raw log files. Assuming you are using a more or less default install, look in the /var/log/suricata/eve.json. You can use grep to extract the alert lines, something like: