Alert Data Fields
Elasticsearch receives NIDS alerts from Suricata via Elastic Agent or Logstash and parses them using:
/opt/so/conf/elasticsearch/ingest/suricata.alert/opt/so/conf/elasticsearch/ingest/common.nids/opt/so/conf/elasticsearch/ingest/commonYou can find these online at:
You can find parsed NIDS alerts in Alerts, Dashboards, Hunt, and Kibana via their predefined queries and dashboards or by manually searching for:
event.module:"suricata"event.dataset:"alert"Those alerts should have the following fields:
source.ipsource.portdestination.ipdestination.portnetwork.transportrule.gidrule.namerule.rulerule.revrule.severityrule.uuidrule.version