Suricata module with remote syslog input


I am unable to configure suricata.yml in filebeat/modules.d to receive suricata logs remotely from syslog instead a local log file.

This post: Using the Filebeat Suricata Module for EVE-Logs in Syslog messages mentions using override input setting, unfortunately I don't know exactly how to do that.

Any help would be appreciated.


This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.