Suricata logs not giving me the full log? integration with wazuh

27 views
Skip to first unread message

Ga Mac

unread,
Sep 16, 2025, 8:30:19 AM (5 days ago) Sep 16
to Wazuh | Mailing List
I tried implementing Suricata based on this link
https://wazuh.com/blog/responding-to-network-attacks-with-suricata-and-wazuh-xdr/

And did all of the following for Ubuntu endpoints which are 22.04 with my wazuh master and indexers in servers. 

The issue is that the dashboard shows the suricata logs but it does not show detailed info like in the link instead shows below. I did a Nmap scan which is this command " sudo nmap -sS <ipaddress>" and it does detect it but not in the way that is helpful as it shows below. Any ideas? I tried a few changes like the changing the decorder limit to 1024.
Screenshot 2025-09-16 164508.png

Olamilekan Abdullateef Ajani

unread,
Sep 16, 2025, 10:05:37 AM (5 days ago) Sep 16
to Wazuh | Mailing List
Hello Gabriel,

Please give me some time to replicate this and provide a feedback accordingly.

regards 

Olamilekan Abdullateef Ajani

unread,
Sep 16, 2025, 3:03:58 PM (4 days ago) Sep 16
to Wazuh | Mailing List
Hello Gabriel,

I apologize for the delayed response. I have replicated this and I can confirm to you that it works. Could you please share the event you received, which is different from what is in the documentation?
And again, you may want to check the eve.json file to ensure you receive the logs, if not, I feel there may be some misconfiguration in the suricata config file, /etc/suricata/suricata.yaml.

Can you please review the configuration and ensure you are listening on the right interface and the right IP address has been supplied too?

Please use the documentation here as a guide and let me know.

Screenshot from 2025-09-16 19-32-26.png
Screenshot from 2025-09-16 19-35-41.png
Screenshot from 2025-09-16 19-36-03.png
Reply all
Reply to author
Forward
0 new messages