Hi!
I’m trying to send alerts from Snort IDS to Elasticsearch, therefore I'm using 3 technologies:
Elasticsearch- https://pastebin.com/uCNMaZFJ
Logstash- https://pastebin.com/zgnbbw9K
Filebeat- https://pastebin.com/45rC3rW5
I am expecting to see snort's alert logs when I check "http://localhost:9200/ola-*/_search?pretty", however nothing is retrieved.
I’m struggling to fix this problem.
Thanks in advance!