# SURICATA LOGS NOT SHOWING UP IN NETWORK EVENTS IN ELASTIC SIEM

**URL:** <https://discuss.elastic.co/t/suricata-logs-not-showing-up-in-network-events-in-elastic-siem/293176>\
**Category:** Endpoint Security\
**Created:** [December 30, 2021, 5:36am UTC](https://discuss.elastic.co/t/suricata-logs-not-showing-up-in-network-events-in-elastic-siem/293176 "2021-12-30T05:36:45Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![mohammadawaisjavaid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammadawaisjavaid/32/60807_2.png) [@mohammadawaisjavaid](https://discuss.elastic.co/u/mohammadawaisjavaid)\
**Post date:** [December 30, 2021, 5:36am UTC](https://discuss.elastic.co/t/suricata-logs-not-showing-up-in-network-events-in-elastic-siem/293176/1 "2021-12-30T05:36:45Z")

</div>

Hi,  
I have installed elastic agent, on my host machine. I created a policy named suricata and I have added integrations of endpoint security and suricata. At the host end I have installed centos and have installed suricata there. Now when I enroll the elastic agent and start it then I see the endpoint security and filebeat logs in host events but did not see any thing in the network events in filebeat. To address this I have mannually installed filebeat on host end and enable suricata and started filebeat. Now the index is showing logs in the discover tab but same index cannot be used in the elastic security where we select metrics and logs index.  
Can any one tell me what exactly the issue is. It will be a great favor indeed. Thankyou

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/3/3329c6e71c527b2a198635a04b19e8bc652d8f08.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/0/40d5119aa66c37455705c7855e878e6a17441001.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/6/065ee2325a66d4016eadeba0354a1a3f51a33483.png)

So far the above screeenshots can describe the issue I am facing. Please give me a remedy on this. My purpose is to visualize the suricata events in the network events in the filebeat like in the host events

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 30, 2021, 4:24pm UTC](https://discuss.elastic.co/t/suricata-logs-not-showing-up-in-network-events-in-elastic-siem/293176/2 "2021-12-30T16:24:06Z")

</div>

Did you run `filebeat setup -e` **before** starting filebeat?

---

<div class="post-metadata">

**Author:** ![mohammadawaisjavaid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammadawaisjavaid/32/60807_2.png) [@mohammadawaisjavaid](https://discuss.elastic.co/u/mohammadawaisjavaid)\
**Post date:** [December 31, 2021, 4:39am UTC](https://discuss.elastic.co/t/suricata-logs-not-showing-up-in-network-events-in-elastic-siem/293176/3 "2021-12-31T04:39:36Z")

</div>

> [@stephenb](#):
>
> `filebeat setup -e`

yes I have tried

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 31, 2021, 5:59am UTC](https://discuss.elastic.co/t/suricata-logs-not-showing-up-in-network-events-in-elastic-siem/293176/4 "2021-12-31T05:59:20Z")

</div>

Ohh I just reread....

So you tried Elastic Agent suricata integration and then filebeat suricata module?

Probably don't want both ...

When you look at the events in Discover are all the suricata fields there? Has the `event.original` been all parsed into individual fields?

If not Perhaps your suricata has a customized format...

---

<div class="post-metadata">

**Author:** ![mohammadawaisjavaid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammadawaisjavaid/32/60807_2.png) [@mohammadawaisjavaid](https://discuss.elastic.co/u/mohammadawaisjavaid)\
**Post date:** [December 31, 2021, 1:23pm UTC](https://discuss.elastic.co/t/suricata-logs-not-showing-up-in-network-events-in-elastic-siem/293176/5 "2021-12-31T13:23:09Z")

</div>

Ok, so you are talking about the version mismatching of suricata integration and actual suricata

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 31, 2021, 3:14pm UTC](https://discuss.elastic.co/t/suricata-logs-not-showing-up-in-network-events-in-elastic-siem/293176/6 "2021-12-31T15:14:45Z")

</div>

Yes perhaps.. are the events all parsed correctly when you look in Discover? Do you see all the individual fields that you would of expect? Or is there just the `event.original` field without all the other separate fields.

You did not answer that.

Also did you make any changes to the Agent or Filebeat config?

Can you post some samples of your suricata logs? (In text not screen shot.. and please format then with the `</>` button

---

<div class="post-metadata">

**Author:** ![mohammadawaisjavaid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammadawaisjavaid/32/60807_2.png) [@mohammadawaisjavaid](https://discuss.elastic.co/u/mohammadawaisjavaid)\
**Post date:** [January 6, 2022, 7:52am UTC](https://discuss.elastic.co/t/suricata-logs-not-showing-up-in-network-events-in-elastic-siem/293176/7 "2022-01-06T07:52:29Z")

</div>

So Far this is the result I am seeing when I go to discover and select filebeat index there  
\<"timestamp":"2022-01-04T19:31:59.384597+0500","event\_type":"stats","stats":{"uptime":542089,"capture":{"kernel\_packets":2,"kernel\_drops":0,"errors":0},"decoder":{"pkts":2,"bytes":120,"invalid":0,"ipv4":2,"ipv6":0,"ethernet":2,"raw":0,"null":0,"sll":0,"tcp":0,"udp":0,"sctp":0,"icmpv4":0,"icmpv6":0,"ppp":0,"pppoe":0,"geneve":0,"gre":0,"vlan":0,"vlan\_qinq":0,"vxlan":0,"ieee8021ah":0,"teredo":0,"ipv4\_in\_ipv6":0,"ipv6\_in\_ipv6":0,"mpls":0,"avg\_pkt\_size":60,"max\_pkt\_size":60,"erspan":0,"event":{"ipv4":{"pkt\_too\_small":0,"hlen\_too\_small":0,"iplen\_smaller\_than\_hlen":0,"trunc\_pkt":0,"opt\_invalid":0,"opt\_invalid\_len":0,"opt\_malformed":0,"opt\_pad\_required":2,"opt\_eol\_required":0,"opt\_duplicate":0,"opt\_unknown":0,"wrong\_ip\_version":0,"icmpv6":0,"frag\_pkt\_too\_large":0,"frag\_overlap":0,"frag\_ignored":0},"icmpv4":{"pkt\_too\_small":0,"unknown\_type":0,"unknown\_code":0,"ipv4\_trunc\_pkt":0,"ipv4\_unknown\_ver":0},"icmpv6":{"unknown\_type":0,"unknown\_code":0,"pkt\_too\_small":0,"ipv6\_unknown\_version":0,"ipv6\_trunc\_pkt":0,"mld\_message\_with\_invalid\_hl":0,"unassigned\_type":0,"experimentation\_type":0},"ipv6":{"pkt\_too\_small":0,"trunc\_pkt":0,"trunc\_exthdr":0,"exthdr\_dupl\_fh":0,"exthdr\_useless\_fh":0,"exthdr\_dupl\_rh":0,"exthdr\_dupl\_hh":0,"exthdr\_dupl\_dh":0,"exthdr\_dupl\_ah":0,"exthdr\_dupl\_eh":0,"exthdr\_invalid\_optlen":0,"wrong\_ip\_version":0,"exthdr\_ah\_res\_not\_null":0,"hopopts\_unknown\_opt":0,"hopopts\_only\_padding":0,"dstopts\_unknown\_opt":0,"dstopts\_only\_padding":0,"rh\_type\_0":0,"zero\_len\_padn":0,"fh\_non\_zero\_reserved\_field":0,"data\_after\_none\_header":0,"unknown\_next\_header":0,"icmpv4":0,"frag\_pkt\_too\_large":0,"frag\_overlap":0,"frag\_ignored":0,"ipv4\_in\_ipv6\_too\_small":0,"ipv4\_in\_ipv6\_wrong\_version":0,"ipv6\_in\_ipv6\_too\_small":0,"ipv6\_in\_ipv6\_wrong\_version":0},"tcp":{"pkt\_too\_small":0,"hlen\_too\_small":0,"invalid\_optlen":0,"opt\_invalid\_len":0,"opt\_duplicate":0},"udp":{"pkt\_too\_small":0,"hlen\_too\_small":0,"hlen\_invalid":0},"sll":{"pkt\_too\_small":0},"ethernet":{"pkt\_too\_small":0},"ppp":{"pkt\_too\_small":0,"vju\_pkt\_too\_small":0,"ip4\_pkt\_too\_small":0,"ip6\_pkt\_too\_small":0,"wrong\_type":0,"unsup\_proto":0},"pppoe":{"pkt\_too\_small":0,"wrong\_code":0,"malformed\_tags":0},"gre":{"pkt\_too\_small":0,"wrong\_version":0,"version0\_recur":0,"version0\_flags":0,"version0\_hdr\_too\_big":0,"version0\_malformed\_sre\_hdr":0,"version1\_chksum":0,"version1\_route":0,"version1\_ssr":0,"version1\_recur":0,"version1\_flags":0,"version1\_no\_key":0,"version1\_wrong\_protocol":0,"version1\_malformed\_sre\_hdr":0,"version1\_hdr\_too\_big":0},"vlan":{"header\_too\_small":0,"unknown\_type":0,"too\_many\_layers":0},"ieee8021ah":{"header\_too\_small":0},"ipraw":{"invalid\_ip\_version":0},"ltnull":{"pkt\_too\_small":0,"unsupported\_type":0},"sctp":{"pkt\_too\_small":0},"mpls":{"header\_too\_small":0,"pkt\_too\_small":0,"bad\_label\_router\_alert":0,"bad\_label\_implicit\_null":0,"bad\_label\_reserved":0,"unknown\_payload\_type":0},"geneve":{"unknown\_payload\_type":0},"erspan":{"header\_too\_small":0,"unsupported\_version":0,"too\_many\_vlan\_layers":0},"dce":{"pkt\_too\_small":0}},"too\_many\_layers":0},"flow":{"memcap":0,"tcp":0,"udp":0,"icmpv4":0,"icmpv6":0,"spare":10000,"emerg\_mode\_entered":0,"emerg\_mode\_over":0,"tcp\_reuse":0,"memuse":7474304},"defrag":{"ipv4":{"fragments":0,"reassembled":0,"timeouts":0},"ipv6":{"fragments":0,"reassembled":0,"timeouts":0},"max\_frag\_hits":0},"flow\_bypassed":{"local\_pkts":0,"local\_bytes":0,"local\_capture\_pkts":0,"local\_capture\_bytes":0,"closed":0,"pkts":0,"bytes":0},"tcp":{"sessions":0,"ssn\_memcap\_drop":0,"pseudo":0,"pseudo\_failed":0,"invalid\_checksum":0,"no\_flow":0,"syn":0,"synack":0,"rst":0,"midstream\_pickups":0,"pkt\_on\_wrong\_thread":0,"segment\_memcap\_drop":0,"stream\_depth\_reached":0,"reassembly\_gap":0,"overlap":0,"overlap\_diff\_data":0,"insert\_data\_normal\_fail":0,"insert\_data\_overlap\_fail":0,"insert\_list\_fail":0,"memuse":2867200,"reassembly\_memuse":491520},"detect":{"engines":[{"id":0,"last\_reload":"2021-12-29T12:57:25.630866+0500","rules\_loaded":23330,"rules\_failed":0}],"alert":0},"app\_layer":{"flow":{"http":0,"ftp":0,"smtp":0,"tls":0,"ssh":0,"imap":0,"smb":0,"dcerpc\_tcp":0,"dns\_tcp":0,"nfs\_tcp":0,"ntp":0,"ftp-data":0,"tftp":0,"ikev2":0,"krb5\_tcp":0,"dhcp":0,"snmp":0,"failed\_tcp":0,"dcerpc\_udp":0,"dns\_udp":0,"nfs\_udp":0,"krb5\_udp":0,"failed\_udp":0},"tx":{"http":0,"ftp":0,"smtp":0,"tls":0,"ssh":0,"imap":0,"smb":0,"dcerpc\_tcp":0,"dns\_tcp":0,"nfs\_tcp":0,"ntp":0,"ftp-data":0,"tftp":0,"ikev2":0,"krb5\_tcp":0,"dhcp":0,"snmp":0,"dcerpc\_udp":0,"dns\_udp":0,"nfs\_udp":0,"krb5\_udp":0},"expectations":0},"flow\_mgr":{"closed\_pruned":0,"new\_pruned":0,"est\_pruned":0,"bypassed\_pruned":0,"flows\_checked":0,"flows\_notimeout":0,"flows\_timeout":0,"flows\_timeout\_inuse":0,"flows\_removed":0,"rows\_checked":65536,"rows\_skipped":65536,"rows\_empty":0,"rows\_busy":0,"rows\_maxlen":0},"http":{"memuse":0,"memcap":0},"ftp":{"memuse":0,"memcap":0},"file\_store":{"open\_files":0}}}/\>

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/0/305279dcbf090ad5ffef9afcd6fea37af2618af7.png)

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 6, 2022, 6:02pm UTC](https://discuss.elastic.co/t/suricata-logs-not-showing-up-in-network-events-in-elastic-siem/293176/8 "2022-01-06T18:02:43Z")

</div>

With respect to the Elastic Agent issue with the Suricata integration, I recommend to verify that the log path is configured correctly. Then check the logs from the Agent (see [View Elastic Agent logs in Fleet | Fleet and Elastic Agent Guide [7.16] | Elastic](https://www.elastic.co/guide/en/fleet/current/elastic-agent-logging.html)) to see if there are any issues. You can share them here if you like.

Also to better help, please share the policy applied to Agent so we can see exactly how it's configured. See [Elastic Agent policies | Fleet and Elastic Agent Guide [7.16] | Elastic](https://www.elastic.co/guide/en/fleet/7.16/agent-policy.html#copy-policy).

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [January 6, 2022, 6:52pm UTC](https://discuss.elastic.co/t/suricata-logs-not-showing-up-in-network-events-in-elastic-siem/293176/9 "2022-01-06T18:52:39Z")

</div>

Thats just Suricata Stats data, its not the actual network logs. The stats data is not shown in the SIEM as its just a metric of what Suricata has done. Have you looked at the eve.json file to see if there is actual data and as Andrew said, is the path to that file correct in the Agent config?

---

<div class="post-metadata">

**Author:** ![mohammadawaisjavaid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammadawaisjavaid/32/60807_2.png) [@mohammadawaisjavaid](https://discuss.elastic.co/u/mohammadawaisjavaid)\
**Post date:** [January 7, 2022, 4:57am UTC](https://discuss.elastic.co/t/suricata-logs-not-showing-up-in-network-events-in-elastic-siem/293176/10 "2022-01-07T04:57:52Z")

</div>

The following is the poilicy with suricata logs integration

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/1/81e2da06d7616ecba5fd60166ebe589a386ee761.png)

here is the path metioned in suricata logs integration

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/4/947bc27820470adb52d15d2d69476194078847cf.png)

This is my suricata.yml in filebeat  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/0/d0101e0db70231427a5f6753f1af9f830f9f698d.png)

This is the file /var/log/suricata/eve.json

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/d/6d1c68c76392516131ae2557f3b907ffc2bca0ee.png)

Now please guide me what should I alter that the logs will appear in the network events where I am going wrong Please guide

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [January 7, 2022, 7:18am UTC](https://discuss.elastic.co/t/suricata-logs-not-showing-up-in-network-events-in-elastic-siem/293176/11 "2022-01-07T07:18:10Z")

</div>

Are u using both the agent and filebeat to read the suricata logs? Are there any errors from either?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 10, 2022, 12:01pm UTC](https://discuss.elastic.co/t/suricata-logs-not-showing-up-in-network-events-in-elastic-siem/293176/12 "2022-01-10T12:01:25Z")

</div>

According to what we have been told the path to the eve.json is correct within the Fleet integration. Can you please check if you have any events by using the Kibana dev console to run this command and post the output:

`GET _cat/indices/logs-suricata*?v`

And please share the Elastic Agent logs.

> [@andrewkroh](#):
>
> Then check the logs from the Agent (see [View Elastic Agent logs in Fleet | Fleet and Elastic Agent Guide [7.16] | Elastic](https://www.elastic.co/guide/en/fleet/current/elastic-agent-logging.html)) to see if there are any issues. You can share them here if you like.

---

<div class="post-metadata">

**Author:** ![mohammadawaisjavaid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammadawaisjavaid/32/60807_2.png) [@mohammadawaisjavaid](https://discuss.elastic.co/u/mohammadawaisjavaid)\
**Post date:** [January 14, 2022, 6:29am UTC](https://discuss.elastic.co/t/suricata-logs-not-showing-up-in-network-events-in-elastic-siem/293176/13 "2022-01-14T06:29:44Z")

</div>

I have used first only elasticagent and added suricata intergration on it in the elastic security but that seems not working. then I have installed filebeat and suricata on the agent machine and then filebeat index has showed logs of suricata but they are not showing in the elasticsearcuty network events

---

<div class="post-metadata">

**Author:** ![mohammadawaisjavaid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammadawaisjavaid/32/60807_2.png) [@mohammadawaisjavaid](https://discuss.elastic.co/u/mohammadawaisjavaid)\
**Post date:** [January 14, 2022, 6:30am UTC](https://discuss.elastic.co/t/suricata-logs-not-showing-up-in-network-events-in-elastic-siem/293176/14 "2022-01-14T06:30:27Z")

</div>

Ok I will check that and will update accordingly

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2022, 6:30am UTC](https://discuss.elastic.co/t/suricata-logs-not-showing-up-in-network-events-in-elastic-siem/293176/15 "2022-02-11T06:30:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
