Hey community, so I just started learning how to configure Suricata and syslog from scratch - that was quite a learning experience. I managed to reach a configuration template that is suitable for me. However, I’m getting both of eve.json alerts, and fast.log alerts, which is redundant. I want to stop sending the fast.log alerts, but I could not find ANY combination or setting change on the config file to stop sending them.
Here’s a photo to show what I mean
The lines that are marked in red are lines I don’t want to send to my QRadar anymore.
And this is my config file:
suricata.yml (72.8 KB)
Help would be highly appreciated. Thank you!