Filebeat is not sending Snort logs to Logstash

Hi!

I’m trying to send alerts from Snort IDS to Elasticsearch, therefore I'm using 3 technologies:

Elasticsearch- https://pastebin.com/uCNMaZFJ
Logstash- https://pastebin.com/zgnbbw9K
Filebeat- https://pastebin.com/45rC3rW5

I am expecting to see snort's alert logs when I check "http://localhost:9200/ola-*/_search?pretty", however nothing is retrieved.

I’m struggling to fix this problem.

Thanks in advance!

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.