Suricata Log Eve JSON

Example using Suricata HoneyPot T-Pot TCE Eve.json

Suricata Log Eve JSON screenshot 1
Suricata Log Eve JSON screenshot 2
Suricata Log Eve JSON screenshot 3
Suricata Log Eve JSON screenshot 4
Suricata Log Eve JSON screenshot 5

Suricata eve JSON format

/etc/suricata/suricata.yaml

Extensible Event Format (nicknamed EVE) event log in JSON format

  • eve-log: enabled: yes filename: eve.json

Promtail config

  • job_name: suricata - json: expressions: event_type: event_type src_ip: src_ip proto: proto dest_port: dest_port alert: - json: expressions: action: action signature_id: signature_id category: category severity: severity source: alert - labels: event_type: src_ip: proto: dest_port: signature_id: signature: category: severity: static_configs:
    • targets:
      • localhost labels: job: suricata_logs path: /var/log/suricata/eve.json

All config available at: https://blog.elhacker.net/2024/11/visualizar-con-grafana-los-eventos-del-ids-suricata-eve-json.html

Revisions
RevisionDescriptionCreated

Get this dashboard

Import the dashboard template

or

Download JSON

Datasource
Dependencies