The Filebeat Suricata module parses Suricata logs, which are mapped to events modeled by the Elastic Common Schema (ECS). This blog post explains how ECS works, and why it exists.
i want to using logstash or redis between filebeat and elastic siem
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.