On Tue, Jun 25, 2019 at 3:14 PM fadi abusafat <fabusa...@gmail.com> wrote:
>
> Hi.
>
> I wish you are fine.
>
> I would like to ask a small help please.
>
> I analysed Pcap file through Suricata command line and it works well but when I tried to see details through Kibana it not works. For example, I designed Visualiz based on SN-Alert details, SN-Alert count, SN-Alerts Severity but no one of them have Data. It looks Kibana does not read from Suricata.
>
> Please, anyone could help me in this issue.
>
> Thank you so much.
>
Seems a double post question - I suggested a way - not sure if you
received the mail or were successful in trying it out ?
> Many Thanks.
>
> Fadi !!!!
>
> --
> IRC: Let's talk about SELKS on Freenode IRC on the #SELKS channel
> Wiki: https://github.com/StamusNetworks/SELKS/wiki
> GitHub: https://github.com/StamusNetworks/SELKS
> Blog: https://www.stamus-networks.com/theblog/
> Twitter: @StamusN
> g+: Stamus Networks
> ---
> You received this message because you are subscribed to the Google Groups "SELKS" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to se...@googlegroups.com.
--
Regards,
Peter Manev
--
IRC: Let's talk about SELKS on Freenode IRC on the #SELKS channel
Wiki: https://github.com/StamusNetworks/SELKS/wiki
GitHub: https://github.com/StamusNetworks/SELKS
Blog: https://www.stamus-networks.com/theblog/
Twitter: @StamusN
g+: Stamus Networks
---
You received this message because you are subscribed to the Google Groups "SELKS" group.
To unsubscribe from this group and stop receiving emails from it, send an email to selks+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/selks/184c05c7-8fcd-4065-acc6-6ab02f1d4230%40googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to se...@googlegroups.com.
Hello,I think what Peter was trying to say is: those current events (2019 as you call them) are probably captured by suricata that is sniffing on the net interface rather then being those from the pcap.
My idea is that the pcap is probably not processed by suricata at all. Can you check the size of eve.json before and after you process the pcap.
Good luck.
On Tuesday, June 25, 2019 at 4:14:03 PM UTC+3, fadi abusafat wrote:Hi.
I wish you are fine.
I would like to ask a small help please.
I analysed Pcap file through Suricata command line and it works well but when I tried to see details through Kibana it not works. For example, I designed Visualiz based on SN-Alert details, SN-Alert count, SN-Alerts Severity but no one of them have Data. It looks Kibana does not read from Suricata.
Please, anyone could help me in this issue.
Thank you so much.
Many Thanks.
Fadi !!!!
--
IRC: Let's talk about SELKS on Freenode IRC on the #SELKS channel
Wiki: https://github.com/StamusNetworks/SELKS/wiki
GitHub: https://github.com/StamusNetworks/SELKS
Blog: https://www.stamus-networks.com/theblog/
Twitter: @StamusN
g+: Stamus Networks
---
You received this message because you are subscribed to the Google Groups "SELKS" group.
To unsubscribe from this group and stop receiving emails from it, send an email to selks+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/selks/d30cc895-fbbf-4b31-92d5-08348c32cc38%40googlegroups.com.