cscli collections install crowdsecurity/suricataA collection for the Suricata IDS/IPS. This collection contains :
fast.log and eve.json formats)Note: Tested with Suricata 6
Example acquisition for this collection :
1filename: /var/log/suricata/eve.json2labels:3 type: suricata-evelogs
or
1filename: /var/log/suricata/fast.log2labels:3 type: suricata-fastlogs
notes :
eve.json should be preferred.