I have installed Logstash, filebeat version 7.9.2, elasticsearch 7.10.0, Elastic Kibana 7.10.0 and Snort 3 everything is up and running I just need to feed my alerts into Elastic Kibana. Snort is monitoring 3 interfaces. So I want to get the alerts in the discovery. Right now Snort is feeding my Elastic by Logstash but the grok is not properly indexing. please see the attached picture. you should use zoom for remote access to my computer for configuring my host.
So I need to to send structured Snort IDS alert logs into ELK.
hi how are you, you are monitoring gpon traffic i guess, i can parse your logs as you want with logstash and send it to elasticsearch, then you can create kibana tables as you want. need to sample logs to parse them firstly then after making ready logstash filter we can work on zoom to configure server itself. thanks good luck
the grok is not working because you have not set up multiline pattern correctly. It is treating each line as a new log, this is why you are getting grok parse failure.
I can help you fix the errors.
I have more than 3 years of experience with Elasticsearch and Logstash data parsing. I can help you in all possible ways.