pfsense suricata alerts log ingestion into SO #9855
Replies: 1 comment 1 reply
-
If you're just wanting to send Suricata alerts, the Suricata filebeat module is what you'll want to utilize. The documentation can be found here: https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-suricata.html, with additional documentation of how to install and configure filebeat on your PFSense platform here: https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-installation-configuration.html |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hello there!
I am fairly new to using SO and SIEMs in general, was wondering the following and I wanted to do some research before starting implementing but couldn't find anything relevant to what I was hoping to do!
I have a pfsense firewall on which I am running suricata with the ETOpen and snort rule sets. If I want the alerts that are raised by suricata on pfsense to be shown in the alerts tab of the security Onion Console, should I use syslog to forward the alerts or use filebeat and to send the alerts to SO?
Please do correct me if my approach is wrong when it comes to ingesting the alerts.
Thanks in advance for any clarification!
Beta Was this translation helpful? Give feedback.
All reactions