# Using the Filebeat Suricata Module for EVE-Logs in Syslog messages

**URL:** <https://discuss.elastic.co/t/using-the-filebeat-suricata-module-for-eve-logs-in-syslog-messages/248064>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [September 9, 2020, 8:15pm UTC](https://discuss.elastic.co/t/using-the-filebeat-suricata-module-for-eve-logs-in-syslog-messages/248064 "2020-09-09T20:15:51Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![nemhods](https://avatars.discourse-cdn.com/v4/letter/n/48db29/32.png) [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Post date:** [September 9, 2020, 8:15pm UTC](https://discuss.elastic.co/t/using-the-filebeat-suricata-module-for-eve-logs-in-syslog-messages/248064/1 "2020-09-09T20:15:51Z")

</div>

Hey,

Filebeat supports extensive Suricata EVE log parsing through the "suricata" module. The assumption of the module is that these logs are present in a file on disk. In my case, they arrive via Syslog. Also, that Syslog does not only contain Suricata events, but also other events like firewall logs (in the same Syslog stream). What's the best way to get this working with filebeat?

I know I can [override the input settings](https://www.elastic.co/guide/en/beats/filebeat/master/advanced-settings.html) for the module and use a Syslog input. But there's more to do here: I need to parse out a syslog header before the data is in plain json like the module expects. Also, I _only_ want to forward those syslog messages to the module, that actually are suricata eve logs.

Is there any way to make Filebeat flexible enough to handle this? In Logstash I would simply check if the log was a suricata log, and then forward it to a "suricata" pipeline with pipeline to pipeline communication.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 7, 2020, 10:16pm UTC](https://discuss.elastic.co/t/using-the-filebeat-suricata-module-for-eve-logs-in-syslog-messages/248064/2 "2020-10-07T22:16:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
