Sidecar to Suricata

Hello guys,

I am trying to use the sidecar to collect suricata-alerts.json and suricata-nsm.json files . Every time i try to get them, the Graylog is showing me empty messages

I also tried with IdsTower , where i can configure Filebeat to send me the json files . Again , i am only receiving empty messages.

Is there anything i need to add to Graylog to parse json ?
Is there a way to get suricata logs with sidecar? please guide.

Best Regards,
Radu

Hey @zapa11

Can you show you configuration made?

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.