Suricata module with remote syslog input

Hello,

I am unable to configure suricata.yml in filebeat/modules.d to receive suricata logs remotely from syslog instead a local log file.

This post: Using the Filebeat Suricata Module for EVE-Logs in Syslog messages mentions using override input setting, unfortunately I don't know exactly how to do that.

Any help would be appreciated.

David

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.