Have a problem with my Suricata + ELK stack

Ok so are you using the suricata filebeat module?

If so there are certain steps / configuration you need for your architecture... Look at this post by me...

It's for ngnix logs but same principles apply.. look at these 2 posts