# Filebeat with Suricata module

**URL:** <https://discuss.elastic.co/t/filebeat-with-suricata-module/270863>\
**Category:** Elasticsearch\
**Created:** [April 21, 2021, 3:13pm UTC](https://discuss.elastic.co/t/filebeat-with-suricata-module/270863 "2021-04-21T15:13:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![nunex\_17](https://avatars.discourse-cdn.com/v4/letter/n/f17d59/32.png) [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Post date:** [April 21, 2021, 3:13pm UTC](https://discuss.elastic.co/t/filebeat-with-suricata-module/270863/1 "2021-04-21T15:13:46Z")

</div>

Hi there!

Here is my question. I have Filebeat sending Suricata logs directly to Elasticsearch (via Suricata module).

My Suricata log files are divided by types of events (eve-alerts, eve-dns, eve-events). In Kibana is configured an index that receives all the messages. Is there any way to use the Suricata module and separate the logs into multiple indexes, just like "Filebeat-alerts" and "Filebeat-events".

Gratefull for any help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2021, 3:14pm UTC](https://discuss.elastic.co/t/filebeat-with-suricata-module/270863/2 "2021-05-19T15:14:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
