File: //usr/share/filebeat/module/suricata/eve/manifest.yml
module_version: 1.0
var:
- name: paths
default:
- /var/log/suricata/eve.json
os.darwin:
- /usr/local/var/log/suricata/eve.json
os.windows:
- 'c:/program files/suricata/log/eve.json'
- name: tags
default: [suricata]
- name: community_id
default: true
- name: internal_networks
default: [ private ]
ingest_pipeline:
- ingest/pipeline.yml
- ingest/dns.yml
- ingest/dns-answer-v1.yml
- ingest/dns-answer-v2.yml
- ingest/tls.yml
- ingest/http.yml
input: config/eve.yml
requires.processors:
- name: geoip
plugin: ingest-geoip
- name: user_agent
plugin: ingest-user-agent