Hello,
I am unable to configure suricata.yml in filebeat/modules.d to receive suricata logs remotely from syslog instead a local log file.
This post: Using the Filebeat Suricata Module for EVE-Logs in Syslog messages mentions using override input setting, unfortunately I don't know exactly how to do that.
Any help would be appreciated.
David