cscli collections install crowdsecurity/suricata
A collection for the Suricata IDS/IPS. This collection contains :
fast.log
and eve.json
formats)Note: Tested with Suricata 6
Example acquisition for this collection :
filename: /var/log/suricata/eve.json
labels:
type: suricata-evelogs
or
filename: /var/log/suricata/fast.log
labels:
type: suricata-fastlogs
notes :
eve.json
should be preferred.