# Suricata-IDS and ELK

**URL:** <https://discuss.elastic.co/t/suricata-ids-and-elk/251725>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 12, 2020, 8:04am UTC](https://discuss.elastic.co/t/suricata-ids-and-elk/251725 "2020-10-12T08:04:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![hack3rcon](https://avatars.discourse-cdn.com/v4/letter/h/96bed5/32.png) [@hack3rcon](https://discuss.elastic.co/u/hack3rcon)\
**Post date:** [October 12, 2020, 8:04am UTC](https://discuss.elastic.co/t/suricata-ids-and-elk/251725/1 "2020-10-12T08:04:09Z")

</div>

Hello,  
I have a Suricata-IDS server and I want to see the logs by ELK. I don't like to install the ELK package on my Suricata-IDS server. I want to know is "Beats" enough for my Suricata-IDS server? How can I harden "Betas"?

Thank you.

---

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [October 12, 2020, 8:09am UTC](https://discuss.elastic.co/t/suricata-ids-and-elk/251725/2 "2020-10-12T08:09:51Z")

</div>

Hi,

> [@hack3rcon](#):
>
> I want to know is "Beats" enough for my Suricata-IDS server?

What do you mean by **enough**? I'm using it for my own Suricata-IDS and it works pretty good.

> [@hack3rcon](#):
>
> How can I harden "Betas"?

You could use [SSL](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html) and [Keystore](https://www.elastic.co/guide/en/beats/filebeat/current/keystore.html) so you don't have to save sensitive information in plain text.

---

<div class="post-metadata">

**Author:** ![hack3rcon](https://avatars.discourse-cdn.com/v4/letter/h/96bed5/32.png) [@hack3rcon](https://discuss.elastic.co/u/hack3rcon)\
**Post date:** [October 12, 2020, 2:30pm UTC](https://discuss.elastic.co/t/suricata-ids-and-elk/251725/3 "2020-10-12T14:30:54Z")

</div>

As I said, I don't like to install any extra packages on Suricata-IDS server. Is "Beats" enough for sending logs to ELK on another server?

---

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [October 12, 2020, 5:15pm UTC](https://discuss.elastic.co/t/suricata-ids-and-elk/251725/4 "2020-10-12T17:15:42Z")

</div>

> [@hack3rcon](#):
>
> Is "Beats" enough for sending logs to ELK on another server?

Sending logs to ELK on another server is what beats are made to do and they're doing it great! so yes they would be enough and you don't need to install any extra packages.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2020, 7:15pm UTC](https://discuss.elastic.co/t/suricata-ids-and-elk/251725/5 "2020-11-09T19:15:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
