# Latest version of Elastic Stack and Suricata examples

**URL:** <https://discuss.elastic.co/t/latest-version-of-elastic-stack-and-suricata-examples/88184>\
**Category:** Logstash\
**Created:** [June 4, 2017, 11:58am UTC](https://discuss.elastic.co/t/latest-version-of-elastic-stack-and-suricata-examples/88184 "2017-06-04T11:58:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![AndrewW](https://avatars.discourse-cdn.com/v4/letter/a/3bc359/32.png) [@AndrewW](https://discuss.elastic.co/u/AndrewW)\
**Post date:** [June 4, 2017, 11:58am UTC](https://discuss.elastic.co/t/latest-version-of-elastic-stack-and-suricata-examples/88184/1 "2017-06-04T11:58:51Z")

</div>

I've got the latest version of suricata 3.2.1 working with EVE json logs  
I followed the woefully out of date instruction on  
[https://redmine.openinfosecfoundation.org/projects/suricata/wiki/\_Logstash\_Kibana\_and\_Suricata\_JSON\_output](https://redmine.openinfosecfoundation.org/projects/suricata/wiki/_Logstash_Kibana_and_Suricata_JSON_output)

The version of Elastic stack i am use is  
ElasticSearch 5.4.1  
Kibana 5.4.1  
LogStash 5.4.1

I've tried several samples config files from this forum and other sites but none work, and i'm totally new to this area.  
my current logstash.conf file looks like

input {  
file {  
path =\> ["/var/log/suricata/eve.json"]  
codec =\> json  
}  
}

filter {  
if [src\_ip] {  
geoip {  
source =\> "src\_ip"  
target =\> "geoip"  
# set database variable to full path to geoip database if you've got  
# the message: "You must specify 'database =\> ...' in your geoip filter"  
#database =\> "/path/to/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float" ]  
}  
}  
}

output {  
stdout { codec =\> rubydebug }  
elasticsearch { embedded =\> true }  
}

What ever i try i keep getting errors like

[2017-06-04T12:10:50,343][ERROR][logstash.agent] Cannot create pipeline {:reason=\>"Expected one of #, ", ', -, [, {,] at line 33, column 22 (byte 778) after input {\n file { \n path =\> ["/var/log/suricata/eve.json"]\n  
sincedb\_path =\> ["}

The line shown (33 in this example changes when i change the conf file

Looking for some guidance on how to get this working.

---

<div class="post-metadata">

**Author:** ![AndrewW](https://avatars.discourse-cdn.com/v4/letter/a/3bc359/32.png) [@AndrewW](https://discuss.elastic.co/u/AndrewW)\
**Post date:** [June 4, 2017, 3:31pm UTC](https://discuss.elastic.co/t/latest-version-of-elastic-stack-and-suricata-examples/88184/2 "2017-06-04T15:31:35Z")

</div>

Trying a different tact i have wipes the reporting apps and installed older version according to [https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-ubuntu-16-04](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-ubuntu-16-04)

everything looks better now except i have no indeces in elastic search

# curl [http://localhost:9200/\_cat/indices](http://localhost:9200/_cat/indices)

yellow open .kibana 5 1 225 1 408.7kb 408.7kb

mu conf file now looks like this  
input {  
file {  
path =\> ["/tmp/eve.json"]  
codec =\> json  
type =\> "SuricataIDPS"  
start\_position =\> "beginning"  
}

}

filter {  
if [type] == "SuricataIDPS" {  
date {  
match =\> ["timestamp", "ISO8601"]  
}  
ruby {  
code =\> "if event['event\_type'] == 'fileinfo'; event['fileinfo']['type']=event['fileinfo']['magic'].to\_s.split(',')[0]; end;"  
}  
}

if [src\_ip] {  
geoip {  
source =\> "src\_ip"  
target =\> "geoip"  
#database =\> "/opt/logstash/vendor/geoip/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float" ]  
}  
if ![geoip.ip] {  
if [dest\_ip] {  
geoip {  
source =\> "dest\_ip"  
target =\> "geoip"  
#database =\> "/opt/logstash/vendor/geoip/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float" ]  
}  
}  
}  
}  
}

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
#protocol =\> http  
}  
}

what have i missed

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 5, 2017, 3:00am UTC](https://discuss.elastic.co/t/latest-version-of-elastic-stack-and-suricata-examples/88184/3 "2017-06-05T03:00:59Z")

</div>

> [@AndrewW](#):
>
> [2017-06-04T12:10:50,343][ERROR][logstash.agent] Cannot create pipeline {:reason=\>"Expected one of #, ", ', -, [, {,] at line 33, column 22 (byte 778) after input {\n file { \n path =\> ["/var/log/suricata/eve.json"]\n  
> sincedb\_path =\> ["}

There doesn't look to be a line 33 in the config, are there other config files?

> [@AndrewW](#):
>
> add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
> add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]

You don't need this, LS creates that automatically.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2017, 3:01am UTC](https://discuss.elastic.co/t/latest-version-of-elastic-stack-and-suricata-examples/88184/4 "2017-07-03T03:01:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
