# HELP! Kibana suricata attack map with attack lines?

**URL:** <https://discuss.elastic.co/t/help-kibana-suricata-attack-map-with-attack-lines/194481>\
**Category:** Kibana\
**Created:** [August 8, 2019, 5:15pm UTC](https://discuss.elastic.co/t/help-kibana-suricata-attack-map-with-attack-lines/194481 "2019-08-08T17:15:34Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![iukea](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iukea/32/49083_2.png) [@iukea](https://discuss.elastic.co/u/iukea)\
**Post date:** [August 8, 2019, 5:15pm UTC](https://discuss.elastic.co/t/help-kibana-suricata-attack-map-with-attack-lines/194481/1 "2019-08-08T17:15:34Z")

</div>

Hello,

I am trying to build some cool looking maps, but I am a bit stumped.

**goal**

- Trying to build an attack map out of Suricata logs
- I have the src\_ip address and the dst\_ip address, and my goal is to do kinda what the "The Nature Conservancy" did.
- Link to there visualization. [https://www.elastic.co/products/maps](https://www.elastic.co/products/maps)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/a/8a233761cec52e958602da8c54d747dbb3c8d2cb.jpeg)

I also have GeoIp data on those Ip addresses. (Lat, long etc)

I can get the little circle and heat maps on the map, but I am stumped on the "lines"/"attack path" that connect the dots together with a line.

I was doing some reading on the Polygon Style properties, but don't know if that is the correct path to go down.

```auto
- running (system specifics)
  - elasticsearch 7.3 (dockered)
  - Kibana 7.3 (dockered)

```

---

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [August 9, 2019, 11:49am UTC](https://discuss.elastic.co/t/help-kibana-suricata-attack-map-with-attack-lines/194481/2 "2019-08-09T11:49:08Z")

</div>

Hi @iukea,

Have you tried to load the demo data [from here](https://github.com/alexfrancoeur/elastic_maps_examples/tree/master/elastic_maps_webinar)? It should give you an idea of what parameters are used to create such a visualization at least. This demo data is from [Elastic Maps for Geospatial Analysis webinar](https://www.elastic.co/webinars/elastic-maps-for-geospatial-analysis) that you can also watch I believe.

Best,  
Oleg

---

<div class="post-metadata">

**Author:** ![iukea](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iukea/32/49083_2.png) [@iukea](https://discuss.elastic.co/u/iukea)\
**Post date:** [August 9, 2019, 9:56pm UTC](https://discuss.elastic.co/t/help-kibana-suricata-attack-map-with-attack-lines/194481/3 "2019-08-09T21:56:06Z")

</div>

Thank you very much! I will try this out here tonight!

---

<div class="post-metadata">

**Author:** ![iukea](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iukea/32/49083_2.png) [@iukea](https://discuss.elastic.co/u/iukea)\
**Post date:** [August 10, 2019, 1:53pm UTC](https://discuss.elastic.co/t/help-kibana-suricata-attack-map-with-attack-lines/194481/4 "2019-08-10T13:53:43Z")

</div>

interesting getting

{"statusCode":400,"error":"Bad Request","message":"child "id" fails because ["id" is not allowed to be empty]","validation":{"source":"params","keys":["id"]}}

when i run the command

```auto
curl -X POST 'http://localhost:5601/api/saved_objects/map/' -H 'Content-Type: application/json' -H "kbn-xsrf: true" -d "@Suricata_Events_Dark.json"

```

---

<div class="post-metadata">

**Author:** ![alexf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexf/32/43211_2.png) [@alexf](https://discuss.elastic.co/u/alexf)\
**Post date:** [August 12, 2019, 5:13pm UTC](https://discuss.elastic.co/t/help-kibana-suricata-attack-map-with-attack-lines/194481/5 "2019-08-12T17:13:06Z")

</div>

Hi @iukea, I just updated the instructions for 7.3. This includes both a map and a dashboard with the map embedded. Check out the latest instructions [here](https://github.com/alexfrancoeur/elastic_maps_examples/tree/master/elastic_maps_webinar). Feel free to reach out if you run into any other issues!

---

<div class="post-metadata">

**Author:** ![iukea](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iukea/32/49083_2.png) [@iukea](https://discuss.elastic.co/u/iukea)\
**Post date:** [August 25, 2019, 2:05am UTC](https://discuss.elastic.co/t/help-kibana-suricata-attack-map-with-attack-lines/194481/6 "2019-08-25T02:05:46Z")

</div>

Hello, I keep on getting the flowing error when I try to add the mapping to my logs. Any suggestions?

```
  {
  "took": 4611,
  "timed_out": false,
  "total": 129784,
  "updated": 0,
  "created": 0,
  "deleted": 0,
  "batches": 1,
  "version_conflicts": 0,
  "noops": 0,
  "retries": {
    "bulk": 0,
    "search": 0
  },
  "throttled_millis": 0,
  "requests_per_second": -1,
  "throttled_until_millis": 0,
  "failures": [
    {
      "index": "devfilebeat-2019.08.20",
      "type": "_doc",
      "id": "zhpJrWwB8yKfK91YDd8i",
      "cause": {
        "type": "mapper_parsing_exception",
        "reason": "object mapping for [source] tried to parse field [source] as object, but found a concrete value"
      },
      "status": 400
    },
    {
      "index": "devfilebeat-2019.08.20",
      "type": "_doc",
      "id": "zxpJrWwB8yKfK91YDd8i",
      "cause": {
        "type": "mapper_parsing_exception",
        "reason": "object mapping for [source] tried to parse field [source] as object, but found a concrete value"
      },
      "status": 400
    },
    {
```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 25, 2019, 3:58pm UTC](https://discuss.elastic.co/t/help-kibana-suricata-attack-map-with-attack-lines/194481/7 "2019-08-25T15:58:54Z")

</div>

> object mapping for [source] tried to parse field [source] as object, but found a concrete value

That looks like you have a missmatch between the mapping definition and the actual data you are trying to ingest.

Perhaps show your mapping and the sample of the data and we might be able to help.

I am a little unclear on

> I keep on getting the flowing error when I try to add the mapping to my logs.

Typically you add the mapping first with an index\_template and then ingest the data there is very few cases when you can update a mapping

> **[Update mapping API | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-mapping.html)**

Perhaps I am miss-understanding

BTW I just loaded @alexf demo data in 7.3.1 worked great!

If you look at that data in Discover you can see the request\_path field which looks like this

```
request_path	

{
  "type": "linestring",
  "coordinates": [
    [
      25.21285,
      45.7816
    ],
    [
      139.691711,
      35.689487
    ]
  ]
}

```

and in the `request_path` mapping in the filebeat mapping you can see the `geo_shape` mapping type

```
"request_path" : {
  "type" : "geo_shape"
}

```

You will need something like that to add to the map to get the lines.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 22, 2019, 3:59pm UTC](https://discuss.elastic.co/t/help-kibana-suricata-attack-map-with-attack-lines/194481/8 "2019-09-22T15:59:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
