# Integrate snort3 with elastic stack using filebeat

**URL:** <https://discuss.elastic.co/t/integrate-snort3-with-elastic-stack-using-filebeat/304749>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 15, 2022, 12:18pm UTC](https://discuss.elastic.co/t/integrate-snort3-with-elastic-stack-using-filebeat/304749 "2022-05-15T12:18:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Onsrm](https://avatars.discourse-cdn.com/v4/letter/o/cc9497/32.png) [@Onsrm](https://discuss.elastic.co/u/Onsrm)\
**Post date:** [May 15, 2022, 12:18pm UTC](https://discuss.elastic.co/t/integrate-snort3-with-elastic-stack-using-filebeat/304749/1 "2022-05-15T12:18:14Z")

</div>

hello,  
i want to integrate snort3 with elk stack. when i use this command :

sudo filebeat setup -E output.logstash.enabled=false -E output.elasticsearch.hosts=['192.168.200.100:9200'] -E setup.kibana.host=192.168.200.100:5601  
i get this error :  
Overwriting ILM policy is disabled. Set `setup.ilm.overwrite: true` for enabling.

Index setup finished.  
Loading dashboards (Kibana must be running and reachable)  
Loaded dashboards  
Setting up ML using setup --machine-learning is going to be removed in 8.0.0. Please use the ML app instead.  
See more: [What is Elastic Machine Learning? | Elastic Docs](https://www.elastic.co/guide/en/machine-learning/current/index.html)  
It is not possble to load ML jobs into an Elasticsearch 8.0.0 or newer using the Beat.  
Exiting: 1 error: Error setting up ML for apache\_ecs: 10 errors: ; ; ; ; ; ; ; ; ;  
this is my filebeat.yml :

============================== Filebeat inputs ===============================

filebeat.inputs:

# Each - is an input. Most options can be set at the input level, so

# you can use different inputs for various configurations.

# Below are the input specific configurations.

# filestream is an input for collecting log messages from files.

- type: log

# ---------------------------- Elasticsearch Output ----------------------------

output.elasticsearch:

# Array of hosts to connect to.

hosts: ["[https://192.168.200.100:9200](https://192.168.200.100:9200)"]

```
 sudo filebeat -e setup :

```

2022-05-15T12:56:58.646+0100 INFO instance/beat.go:685 Home path: [/usr/share/filebeat] Config path: [/etc/filebeat] Data path: [/var/lib/filebeat] Logs path: [/var/log/filebeat] Hostfs Path: [/]  
2022-05-15T12:56:58.657+0100 INFO instance/beat.go:693 Beat ID: e805a936-a384-47e9-a062-dd3b6bcde065  
2022-05-15T12:57:01.726+0100 WARN [add\_cloud\_metadata] add\_cloud\_metadata/provider\_aws\_ec2.go:79 read token request for getting IMDSv2 token returns empty: Put "[http://169.254.169.254/latest/api/token](http://169.254.169.254/latest/api/token)": context deadline exceeded (Client.Timeout exceeded while awaiting headers). No token in the metadata request will be used.  
2022-05-15T12:57:01.730+0100 INFO [beat] instance/beat.go:1039 Beat info {"system\_info": {"beat": {"path": {"config": "/etc/filebeat", "data": "/var/lib/filebeat", "home": "/usr/share/filebeat", "logs": "/var/log/filebeat"}, "type": "filebeat", "uuid": "e805a936-a384-47e9-a062-dd3b6bcde065"}}}  
2022-05-15T12:57:01.732+0100 INFO [beat] instance/beat.go:1048 Build info {"system\_info": {"build": {"commit": "1993ee88a11cb34f61a1fb45c7c3cf50533682cb", "libbeat": "7.17.3", "time": "2022-04-19T09:27:20.000Z", "version": "7.17.3"}}}  
2022-05-15T12:57:01.734+0100 INFO [beat] instance/beat.go:1051 Go runtime info {"system\_info": {"go": {"os":"linux","arch":"amd64","max\_procs":1,"version":"go1.17.8"}}}  
2022-05-15T12:57:01.736+0100 INFO [beat] instance/beat.go:1055 Host info {"system\_info": {"host": {"architecture":"x86\_64","boot\_time":"2022-05-15T08:47:04+01:00","containerized":false,"name":"ids-VirtualBox","ip":["127.0.0.1/8","::1/128","192.168.200.50/24","fe80::748c:4f53:7b00:9a66/64","192.168.1.10/24","fe80::fb65:6477:4d28:31e1/64"],"kernel\_version":"5.13.0-41-generic","mac":["08:00:27:3c:6b:bb","08:00:27:0a:b4:f4"],"os":{"type":"linux","family":"debian","platform":"ubuntu","name":"Ubuntu","version":"20.04.4 LTS (Focal Fossa)","major":20,"minor":4,"patch":4,"codename":"focal"},"timezone":"CET","timezone\_offset\_sec":3600,"id":"883cf7ca5e9a40af9ef50059f8204fe7"}}}  
2022-05-15T12:57:01.738+0100 INFO [beat] instance/beat.go:1084 Process info {"system\_info": {"process": {"capabilities": {"inheritable":null,"permitted":["chown","dac\_override","dac\_read\_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux\_immutable","net\_bind\_service","net\_broadcast","net\_admin","net\_raw","ipc\_lock","ipc\_owner","sys\_module","sys\_rawio","sys\_chroot","sys\_ptrace","sys\_pacct","sys\_admin","sys\_boot","sys\_nice","sys\_resource","sys\_time","sys\_tty\_config","mknod","lease","audit\_write","audit\_control","setfcap","mac\_override","mac\_admin","syslog","wake\_alarm","block\_suspend","audit\_read","38","39","40"],"effective":["chown","dac\_override","dac\_read\_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux\_immutable","net\_bind\_service","net\_broadcast","net\_admin","net\_raw","ipc\_lock","ipc\_owner","sys\_module","sys\_rawio","sys\_chroot","sys\_ptrace","sys\_pacct","sys\_admin","sys\_boot","sys\_nice","sys\_resource","sys\_time","sys\_tty\_config","mknod","lease","audit\_write","audit\_control","setfcap","mac\_override","mac\_admin","syslog","wake\_alarm","block\_suspend","audit\_read","38","39","40"],"bounding":["chown","dac\_override","dac\_read\_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux\_immutable","net\_bind\_service","net\_broadcast","net\_admin","net\_raw","ipc\_lock","ipc\_owner","sys\_module","sys\_rawio","sys\_chroot","sys\_ptrace","sys\_pacct","sys\_admin","sys\_boot","sys\_nice","sys\_resource","sys\_time","sys\_tty\_config","mknod","lease","audit\_write","audit\_control","setfcap","mac\_override","mac\_admin","syslog","wake\_alarm","block\_suspend","audit\_read","38","39","40"],"ambient":null}, "cwd": "/home/ids", "exe": "/usr/share/filebeat/bin/filebeat", "name": "filebeat", "pid": 10782, "ppid": 10781, "seccomp": {"mode":"disabled","no\_new\_privs":false}, "start\_time": "2022-05-15T12:56:56.690+0100"}}}  
2022-05-15T12:57:01.741+0100 INFO instance/beat.go:328 Setup Beat: filebeat; Version: 7.17.3  
2022-05-15T12:57:01.742+0100 INFO [index-management] idxmgmt/std.go:184 Set output.elasticsearch.index to 'filebeat-7.17.3' as ILM is enabled.  
2022-05-15T12:57:01.746+0100 INFO [esclientleg] eslegclient/connection.go:105 elasticsearch url: [https://192.168.200.100:9200](https://192.168.200.100:9200)  
2022-05-15T12:57:01.760+0100 INFO [publisher] pipeline/module.go:113 Beat name: ids-VirtualBox  
2022-05-15T12:57:01.780+0100 INFO [add\_cloud\_metadata] add\_cloud\_metadata/add\_cloud\_metadata.go:101 add\_cloud\_metadata: hosting provider type not detected.  
2022-05-15T12:57:01.869+0100 INFO [esclientleg] eslegclient/connection.go:105 elasticsearch url: [https://192.168.200.100:9200](https://192.168.200.100:9200)  
2022-05-15T12:57:01.880+0100 ERROR [esclientleg] transport/logging.go:37Error dialing tls: first record does not look like a TLS handshake {"network": "tcp", "address": "192.168.200.100:9200"}  
2022-05-15T12:57:01.887+0100 ERROR [esclientleg] eslegclient/connection.go:231 error connecting to Elasticsearch at [https://192.168.200.100:9200](https://192.168.200.100:9200): Get "[https://192.168.200.100:9200](https://192.168.200.100:9200)": http: server gave HTTP response to HTTPS client  
2022-05-15T12:57:01.887+0100 ERROR instance/beat.go:1014 Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: [error connecting to Elasticsearch at [https://192.168.200.100:9200](https://192.168.200.100:9200): Get "[https://192.168.200.100:9200](https://192.168.200.100:9200)": http: server gave HTTP response to HTTPS client]  
Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: [error connecting to Elasticsearch at [https://192.168.200.100:9200](https://192.168.200.100:9200): Get "[https://192.168.200.100:9200](https://192.168.200.100:9200)": http: server gave HTTP response to HTTPS client]

```
curl -XGET 'http://192.168.200.100:9200/filebeat-*/_search?pretty'

```

{  
"took" : 1,  
"timed\_out" : false,  
"\_shards" : {  
"total" : 1,  
"successful" : 1,  
"skipped" : 0,  
"failed" : 0  
},  
"hits" : {  
"total" : {  
"value" : 0,  
"relation" : "eq"  
},  
"max\_score" : null,  
"hits" :   
}  
}

```
curl -XGET 'http://192.168.200.100:9200/?pretty'

```

{  
"name" : "node-1",  
"cluster\_name" : "elasticsearch",  
"cluster\_uuid" : "jUKN1EpIQmOBD7eCl2skPw",  
"version" : {  
"number" : "7.17.2",  
"build\_flavor" : "default",  
"build\_type" : "deb",  
"build\_hash" : "de7261de50d90919ae53b0eff9413fd7e5307301",  
"build\_date" : "2022-03-28T15:12:21.446567561Z",  
"build\_snapshot" : false,  
"lucene\_version" : "8.11.1",  
"minimum\_wire\_compatibility\_version" : "6.8.0",  
"minimum\_index\_compatibility\_version" : "6.0.0-beta1"  
},  
"tagline" : "You Know, for Search"  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 16, 2022, 12:19am UTC](https://discuss.elastic.co/t/integrate-snort3-with-elastic-stack-using-filebeat/304749/2 "2022-05-16T00:19:02Z")

</div>

Please format your code/logs/config using the `</>` button, or markdown style back ticks. It helps to make things easy to read which helps us help you 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 13, 2022, 2:19am UTC](https://discuss.elastic.co/t/integrate-snort3-with-elastic-stack-using-filebeat/304749/3 "2022-06-13T02:19:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
