# Elasticsearch generates lots of Suricate events

**URL:** https://discuss.elastic.co/t/elasticsearch-generates-lots-of-suricate-events/37638
**Category:** Elasticsearch
**Created:** [December 20, 2015, 5:01am UTC](https://discuss.elastic.co/t/elasticsearch-generates-lots-of-suricate-events/37638 "2015-12-20T05:01:13Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![NullOranje](https://avatars.discourse-cdn.com/v4/letter/n/8491ac/32.png) [@NullOranje](https://discuss.elastic.co/u/NullOranje)
#### Post date: [December 20, 2015, 5:01am UTC](https://discuss.elastic.co/t/elasticsearch-generates-lots-of-suricate-events/37638/1 "2015-12-20T05:01:13Z")

</div>

I've setup an ELK stack to parse Suricate log events, but I'm having a problem with Elasticsearch generating too much data. Every few seconds, it generates several log events such as

> {"timestamp":"2015-12-20T04:56:07.588866","event\_type":"fileinfo","src\_ip":"127.0.0.1","src\_port":40901,"dest\_ip":"127.0.0.1","dest\_port":9200,"proto":"TCP","http":{"url":"/\_bulk","hostname":"localhost","http\_user\_agent":"Manticore 0.4.4"},"fileinfo":{"filename":"/\_bulk","magic":"ASCII text, with very long lines","state":"CLOSED","stored":false,"size":3898}}  
> {"timestamp":"2015-12-20T04:56:07.599335","event\_type":"http","src\_ip":"127.0.0.1","src\_port":40901,"dest\_ip":"127.0.0.1","dest\_port":9200,"proto":"TCP","http":{"hostname":"localhost","url":"/\_bulk","http\_user\_agent":"Manticore 0.4.4","accept\_encoding":"gzip,deflate"}}

I'm not sure how to suppress this information. Thoughts?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [December 21, 2015, 3:21am UTC](https://discuss.elastic.co/t/elasticsearch-generates-lots-of-suricate-events/37638/2 "2015-12-21T03:21:12Z")

</div>

The only way to suppress it is to not send it to ES.  
You could put LS in the mix and then filter these out.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 11:29pm UTC](https://discuss.elastic.co/t/elasticsearch-generates-lots-of-suricate-events/37638/3 "2017-07-05T23:29:42Z")

</div>


