# Suricata and Kibana in Ubuntu 18.04

**URL:** <https://discuss.elastic.co/t/suricata-and-kibana-in-ubuntu-18-04/235438>\
**Category:** Kibana\
**Created:** [June 3, 2020, 1:38am UTC](https://discuss.elastic.co/t/suricata-and-kibana-in-ubuntu-18-04/235438 "2020-06-03T01:38:41Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![wahyu\_wir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wahyu_wir/32/69601_2.png) [@wahyu\_wir](https://discuss.elastic.co/u/wahyu_wir)\
**Post date:** [June 3, 2020, 1:38am UTC](https://discuss.elastic.co/t/suricata-and-kibana-in-ubuntu-18-04/235438/1 "2020-06-03T01:38:41Z")

</div>

how can I use ELK on the suricata that I installed on Ubuntu 18.04?

I have followed the link: [https://www.google.com/amp/s/logz.io/blog/network-security-monitoring/amp/](https://www.google.com/amp/s/logz.io/blog/network-security-monitoring/amp/)

but after the kibana is opened, it appears that it cannot define index pattern

---

<div class="post-metadata">

**Author:** ![Camilo\_Diaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/camilo_diaz/32/46512_2.png) [@Camilo\_Diaz](https://discuss.elastic.co/u/Camilo_Diaz)\
**Post date:** [June 3, 2020, 4:35am UTC](https://discuss.elastic.co/t/suricata-and-kibana-in-ubuntu-18-04/235438/2 "2020-06-03T04:35:52Z")

</div>

so are you sending the logs with filebeats?

You might need to load the ingest pipeline from filebeats (It needs a connection to elasticsearch)

The command is:  
filebeat setup --pipelines --modules suricata

---

<div class="post-metadata">

**Author:** ![wahyu\_wir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wahyu_wir/32/69601_2.png) [@wahyu\_wir](https://discuss.elastic.co/u/wahyu_wir)\
**Post date:** [June 3, 2020, 11:13am UTC](https://discuss.elastic.co/t/suricata-and-kibana-in-ubuntu-18-04/235438/3 "2020-06-03T11:13:05Z")

</div>

thank you Camilo Diaz for ur response, I'll try it.

i'm trying to use filebeat suricata module to send logs to logstash and then to kibana visualitation.

---

<div class="post-metadata">

**Author:** ![wahyu\_wir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wahyu_wir/32/69601_2.png) [@wahyu\_wir](https://discuss.elastic.co/u/wahyu_wir)\
**Post date:** [June 3, 2020, 1:07pm UTC](https://discuss.elastic.co/t/suricata-and-kibana-in-ubuntu-18-04/235438/4 "2020-06-03T13:07:09Z")

</div>

I've tried it on my project,

when i write the command:  
filebeat setup --pipelines --modules suricata

appears like this:

Exiting: error loading config file: yaml: line 30: did not find expected '-' indicator

for my filebeat.yml settings as in the picture that I attached

 ![Screenshot from 2020-06-03 19-57-58](https://us1.discourse-cdn.com/elastic/original/3X/3/c/3c2c636ba5d8af16ed0a3963e2ed9226fb089dcf.png)

---

<div class="post-metadata">

**Author:** ![wahyu\_wir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wahyu_wir/32/69601_2.png) [@wahyu\_wir](https://discuss.elastic.co/u/wahyu_wir)\
**Post date:** [June 3, 2020, 1:13pm UTC](https://discuss.elastic.co/t/suricata-and-kibana-in-ubuntu-18-04/235438/5 "2020-06-03T13:13:28Z")

</div>

kibana status is green and the user is the same as on my computer,

but i create discover and than index pattern  
appeared the same as before like =\> Couldn't find any Elasticsearch data

sorry for disturbing your time ☹

---

<div class="post-metadata">

**Author:** ![Camilo\_Diaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/camilo_diaz/32/46512_2.png) [@Camilo\_Diaz](https://discuss.elastic.co/u/Camilo_Diaz)\
**Post date:** [June 3, 2020, 8:39pm UTC](https://discuss.elastic.co/t/suricata-and-kibana-in-ubuntu-18-04/235438/6 "2020-06-03T20:39:52Z")

</div>

If you use modules, then the config should be on /etc/filebeat/modules.d/suricata.yml

From your screenshot I see the config is on filebeat.yml which is not correct.

Maybe start over with your filebeat.yml and have a look at the documentation.

---

<div class="post-metadata">

**Author:** ![wahyu\_wir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wahyu_wir/32/69601_2.png) [@wahyu\_wir](https://discuss.elastic.co/u/wahyu_wir)\
**Post date:** [June 27, 2020, 11:29am UTC](https://discuss.elastic.co/t/suricata-and-kibana-in-ubuntu-18-04/235438/7 "2020-06-27T11:29:47Z")

</div>

the module I've activated is needed.

After I restarted Filebeat and Kibana, I finally got it. thxyu @Camilo_Diaz

but a new problem arises, is there a setting for the request process?

when the initial kibana can detect within 30 minutes, a warning appears No results match your search criteria.

how about this?

thank you

 ![Screenshot from 2020-06-27 18-27-18](https://us1.discourse-cdn.com/elastic/original/3X/2/7/27ffc03f4997329902f05b468e313bd7d567da34.png) ![Screenshot from 2020-06-27 18-27-24](https://us1.discourse-cdn.com/elastic/original/3X/6/6/6694065f57f15c9b6cc2aaa98b8cb41767cea719.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 25, 2020, 11:29am UTC](https://discuss.elastic.co/t/suricata-and-kibana-in-ubuntu-18-04/235438/8 "2020-07-25T11:29:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
