Hi,
Suricata does’t send logs to splunk in json file format and sends it in syslog format
can anybody help to to solve the problem?
thanks,
Hi,
Suricata does’t send logs to splunk in json file format and sends it in syslog format
can anybody help to to solve the problem?
thanks,
What version of Suricata are you using?
Please share your suricata config file (suricata.yaml)
version: 6.0.10
suricata.yaml (73.0 KB)
First, Suricata 6.0.10 is EOL and is not supported.
The suricata configuration file shows that eve.json is being created and will contain logs and alerts from suricata.
Suricata isn’t involved in log export; it creates and populates the files as it processes packets.