# Logstash an suricata

**URL:** <https://discuss.elastic.co/t/logstash-an-suricata/268133>\
**Category:** Logstash\
**Created:** [March 23, 2021, 7:11pm UTC](https://discuss.elastic.co/t/logstash-an-suricata/268133 "2021-03-23T19:11:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lumi](https://avatars.discourse-cdn.com/v4/letter/l/b38774/32.png) [@lumi](https://discuss.elastic.co/u/lumi)\
**Post date:** [March 23, 2021, 7:11pm UTC](https://discuss.elastic.co/t/logstash-an-suricata/268133/1 "2021-03-23T19:11:19Z")

</div>

Hello

I am getting Suricata Messages from Qradar which i need so save in a file.  
The suricata module on filebeat will add it to the elasticsearch.

i have the following problem:

This is what logstash writes into the file when i use the the normal input and outpout (without filters or anything)

> **{"@version":"1","host":"x.x.x.x","@timestamp":"2021-03-23T18:20:29.702Z","message":"\<174\>Mar 23 19:21:05 hostxxx suricata[23719]:** {"timestamp":"2021-03-23T19:21:05.688188+0100","flow\_id":130516297813980,"in\_iface":"eth3","event\_type":"alert","src\_ip":"x.x.x.x","src\_port":xx,"dest\_ip":"x.x.x.x","dest\_port":x,"proto":"xxx","alert":{"action":"allowed","gid":1,"signature\_id":2xxxx,"rev":xxx,"signature":"ET COMPROMISED Known Compromised or Hostile Host Traffic group xx","category":"Misc Attack","severity":2,"metadata":{"affected\_product":["Any"],"attack\_target":["Any"],"created\_at":["20xx\_xx\_xx"],"deployment":["Perimeter"],"signature\_severity":["Major"],"tag":["COMPROMISED"],"updated\_at":["2021\_xx\_xx"]}},"dns":{"query":[{"type":"query","id":xxxx,"rrname":"xxxx.xxxx..xx","rrtype":"A","tx\_id":0}]},"app\_proto":"xxx","flow":{"pkts\_toserver":1,"pkts\_toclient":0,"bytes\_toserver":87,"bytes\_toclient":0,"start":"2021-03-23T19:21:05.688188+0100"}}\n"}

When I add the codec plugin "plain", then i get the following output into the file:

> **2021-03-23T18:33:21.265Z xx.x.x.x \<174\>Mar 23 19:33:57 xxxx suricata[23719]:** {"timestamp":"2021-03-23T19:33:57.340639+0100","flow\_id":xxxxx719,"in\_iface":"eth3","event\_type":"alert","src\_ip":"xxxxx:XXXx:xxxx....","src\_port":xxx,"dest\_ip":"xxx:Xxxxx:XXxxx:Xxxxx1","dest\_port":xxxx,"proto":"XXX","tx\_id":0,"alert":{"action":"allowed","gid":1,"signature\_id":yyyyy,"rev":2,"signature":"XXXXX","category":"XX yyy xxx yy","severity":1,"metadata":{"created\_at":["2011\_03\_21"],"updated\_at":["2019\_09\_28"]}},"dns":{"query":[{"type":"query","id":48604,"rrname":"1y.xxx.xxx.xxx","rrtype":"A","tx\_id":0}]},"app\_proto":"dns","flow":{"pkts\_toserver":1,"pkts\_toclient":0,"bytes\_toserver":117,"bytes\_toclient":0,"start":"2021-03-23T19:33:57.340639+0100"}}

I need to remove the line before {"timestamp"

This needs to be removed otherwise Filebeat suricata module does not work.

```auto
2021-03-23T18:33:21.265Z xx.x.x.x <174>Mar 23 19:33:57 xxxx suricata[23719]:

```

The text till \<174\> is automatically attached from logstash

```auto
2021-03-23T18:33:21.265Z xx.x.x.x 

```

Has anybody any idea how to solve this problem?  
is maybe logstash unable ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 23, 2021, 7:20pm UTC](https://discuss.elastic.co/t/logstash-an-suricata/268133/2 "2021-03-23T19:20:45Z")

</div>

> [@lumi](#):
>
> The text till \<174\> is automatically attached from logstash

If you do not specify the message format then the plain codec [calls .to\_s](https://github.com/logstash-plugins/logstash-codec-plain/blob/b60b84edb41cc094bb7afb0e3bec4f3bc25da051/lib/logstash/codecs/plain.rb#L39) on the event to generate the output. The [toString method](https://github.com/elastic/logstash/blob/c588c42dcf0243fb0615f214fafd011b069d94b0/logstash-core/src/main/java/org/logstash/Event.java#L351) of the event concatenates the timestamp, host field and message field.

You could try

```
codec => plain { format => "%{message}" }

```

---

<div class="post-metadata">

**Author:** ![lumi](https://avatars.discourse-cdn.com/v4/letter/l/b38774/32.png) [@lumi](https://discuss.elastic.co/u/lumi)\
**Post date:** [March 23, 2021, 9:05pm UTC](https://discuss.elastic.co/t/logstash-an-suricata/268133/3 "2021-03-23T21:05:01Z")

</div>

Hi Badger

Thank you very much for your help !

Now i fixed it with the grok filter

```
 grok {
        match => {"message" => "%{SYSLOG5424PRI}%{SYSLOGBASE}%{SPACE}%{GREEDYDATA:xxx}"}
   }

output {
 file {
   path => "/var/lib/suricata/suricata.log"
   codec => plain { format => "%{xxx}" }
 }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2021, 9:05pm UTC](https://discuss.elastic.co/t/logstash-an-suricata/268133/4 "2021-04-20T21:05:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
