SELKS icon indicating copy to clipboard operation
SELKS copied to clipboard

SELKS/Suricata output to another probe or SOC

Open michal25 opened this issue 1 year ago • 1 comments
trafficstars

Is there an existing feature request that has already been created?

  • [X] I have searched the exiting features requests

Is your feature request related to a problem? Please describe.

My question is. Is it possible to forward SELKS/Suricata output to another probe or SOC?

Destination probe will mark the data as Probe1, Probe2 etc.

Searching machines will find issues with answer yes, but no text about HOW. For example snort / barnyard had this possibility and it was very useful.

Describe the solution you would like?

URL to manual how to use the options in the suricata.yaml configuration file.

Alternative Solutions

No response

Additional Context

No response

michal25 avatar May 29 '24 09:05 michal25

Yes, you can do that on any suricata install - just use filebeat for example to forward the logs.

pevma avatar May 30 '24 19:05 pevma