OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • How can we export suricata alerts as syslog/raw udp ?
« previous next »
  • Print
Pages: [1]

Author Topic: How can we export suricata alerts as syslog/raw udp ?  (Read 1119 times)

jsksingh88

  • Newbie
  • *
  • Posts: 1
  • Karma: 0
    • View Profile
How can we export suricata alerts as syslog/raw udp ?
« on: March 28, 2023, 04:47:51 pm »
I am running

OPNsense 23.1.4_1-amd64
FreeBSD 13.1-RELEASE-p7
OpenSSL 1.1.1t 7 Feb 2023

and looking for a way to stream out IDS alerts into an elastic stack that I have running locally. At the moment, I have a syslog receiver getting other logs from opnsense like filter and dhcp but there are no IDS alerts in there. In the logging target setting, it is set to send all services and all levels. How can I achieve this ?
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • How can we export suricata alerts as syslog/raw udp ?
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2