# Suricata with ElasticStack

**URL:** <https://discuss.elastic.co/t/suricata-with-elasticstack/141948>\
**Category:** Elasticsearch\
**Created:** [July 27, 2018, 12:53pm UTC](https://discuss.elastic.co/t/suricata-with-elasticstack/141948 "2018-07-27T12:53:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![DK1206](https://avatars.discourse-cdn.com/v4/letter/d/b487fb/32.png) [@DK1206](https://discuss.elastic.co/u/DK1206)\
**Post date:** [July 27, 2018, 12:53pm UTC](https://discuss.elastic.co/t/suricata-with-elasticstack/141948/1 "2018-07-27T12:53:21Z")

</div>

Hey guys,

**OVERVIEW**  
I managed to set up ElasticStack on my Ubuntu VM (my host is Windows). I installed on my host Sysmon and succesfully connected it with winlogbeat. I can now see in Kibana UI Winlogbeat logs - this is awesome. However, now I want to expand my ElasticStack to get closer to my goal - have an open source SIEM working.  
I want to add Suricata / Snort / Bro as my data sources. But I tried installing Bro with guides I found here:  
[BRO with ELK](https://logz.io/blog/bro-elk-part-1/)  
and I was not succesful, I could not see any Bro logs although in Kibana I could find logstash index pattern, but in my 'Discover' tab, there was still only Sysmon logs, even if I switched to different index.  
Then I went to try and install Suricata with the help of following guide:  
[Suricata with ELK](https://redmine.openinfosecfoundation.org/projects/suricata/wiki/_logstash_kibana_and_suricata_json_output)  
I seem to get the eve.json file populated with logs, but I cannot display them in Kibana. I dont want to install one of those templates, because I already have some Dashboards configured for my Sysmon and don't want to lose that.

**QUESTION**  
Since I do not have any error output and the question 'What is wrong?' would be probably too general to ask. I am asking for a validated URL to a video/tutorial/blog, where I can get step-by-step instruction on how to add Suricata / Snort / Bro to my existing ElasticStack with my Winlogbeat running already.

Any suggestion would be greatly appreciated.

Thanks.

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [August 4, 2018, 10:46am UTC](https://discuss.elastic.co/t/suricata-with-elasticstack/141948/2 "2018-08-04T10:46:27Z")

</div>

Try this for Suricata...

> **[koiossian/synesis\_lite\_suricata](https://github.com/koiossian/synesis_lite_suricata)**
>
> synesis\_lite\_suricata - Suricata IDS/IPS log analytics using the Elastic Stack.

And this for Snort...

> **[koiossian/synesis\_lite\_snort](https://github.com/koiossian/synesis_lite_snort)**
>
> synesis\_lite\_snort - Snort IDS/IPS log analytics using the Elastic Stack.

Both solutions use filebeat to send the raw logs to Logstash where it is processed and sent to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2018, 10:47am UTC](https://discuss.elastic.co/t/suricata-with-elasticstack/141948/3 "2018-09-01T10:47:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
