I am trying to filter snort alerts. I need to display the output on kibana dashboard. I have created the filtering script "logstash_snort.conf" in /opt/bitnami/logstash/conf directory. logstash is running fine, however, it seems snort alerts are not filtered.
type => snort
port => 5044
I am assuming the port is the same as indicated in our filebeat file.
Should I modify logstash.conf ??