# Suricata Module missing mapping for tenant\_id

**URL:** <https://discuss.elastic.co/t/suricata-module-missing-mapping-for-tenant-id/226708>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [April 6, 2020, 12:27pm UTC](https://discuss.elastic.co/t/suricata-module-missing-mapping-for-tenant-id/226708 "2020-04-06T12:27:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![stormrider959](https://avatars.discourse-cdn.com/v4/letter/s/dc4da7/32.png) [@stormrider959](https://discuss.elastic.co/u/stormrider959)\
**Post date:** [April 6, 2020, 12:27pm UTC](https://discuss.elastic.co/t/suricata-module-missing-mapping-for-tenant-id/226708/1 "2020-04-06T12:27:16Z")

</div>

Hello everybody

I'm posting this here because the contributing guidelines on GitHub state that issues should be posted here before opening one on GitHub.

The Suricata Filebeat Module is missing a mapping for the field "tenant\_id". Can you please add a mapping to the module?

When using the multi tenancy feature from Suricata (see [https://suricata.readthedocs.io/en/suricata-5.0.2/configuration/multi-tenant.html](https://suricata.readthedocs.io/en/suricata-5.0.2/configuration/multi-tenant.html)) the tenant ID is indicated in the field suricata.eve.alert.tenant\_id.

example alert (sanitized):

```auto
{
    "timestamp":"2020-03-31T15:32:43.000579+0200",
    "flow_id":255379933845494,
    "in_iface":"eno2",
    "event_type":"alert",
    "vlan":[1900],
    "src_ip":"4.3.2.1",
    "src_port":54321,
    "dest_ip":"192.168.1.2",
    "dest_port":80,
    "proto":"TCP",
    "metadata":{
        "flowints":{
            "http.anomaly.count":1
        }
    },
    "tx_id":0,
    "alert":{
        "action":"allowed",
        "gid":1,
        "signature_id":2221014,
        "rev":1,
        "signature":"SURICATA HTTP missing Host header",
        "category":"Generic Protocol Command Decode",
        "severity":3,
        "tenant_id":1
    },
    "http":{
        "url":"\/someURL",
        "http_user_agent":"agent",
        "http_method":"POST",
        "protocol":"HTTP\/1.1",
        "length":0
    },
    "app_proto":"http",
    "flow":{
        "pkts_toserver":5,
        "pkts_toclient":3,
        "bytes_toserver":691,
        "bytes_toclient":321,
        "start":"2020-03-31T15:31:41.415734+0200"
    },
    "packet_info":{
        "linktype":12
    }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 4, 2020, 12:27pm UTC](https://discuss.elastic.co/t/suricata-module-missing-mapping-for-tenant-id/226708/2 "2020-05-04T12:27:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
