Forwarding Suricata Events (alerts) to External SIEM #10536
Replies: 2 comments
-
You probably want to use these instructions instead: https://docs.securityonion.net/en/latest/logstash.html#original-event-forwarding Try this for the custom pipeline:
|
Beta Was this translation helpful? Give feedback.
0 replies
-
did you get this working?? seems like the pipeline conf is getting removed at every restart, I suppose something has to be done on the salt. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
I folowed the link https://docs.securityonion.net/en/latest/logstash.html?highlight=forwarding#modified-event-forwarding for this topic, but didnt have much success. Any such inputs will be appreciated.
Beta Was this translation helpful? Give feedback.
All reactions