Hi,
I have already configured Suricata logs to be fowarded to ES through Filebeat. I am receiving the logs but this message still appears. I am using the Suricata module aswell
Hi,
I have already configured Suricata logs to be fowarded to ES through Filebeat. I am receiving the logs but this message still appears. I am using the Suricata module aswell
Which version of the Elastic stack are you using? And can you show an example from the Discover page that the suricata data is being ingested, just to ensure it enters correctly?
If the data is ingested then the bug is maybe just with the "Check Data" button. This wizard is just to help setting it up, so you can exit the page in the meantime, it does not have to pass
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.