Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
output-json: update timestamp format
This patch updates the timestamp format used in eve loggin. It uses a ISO 8601 comptatible string. This allow tools parsing the output to easily detect adn/or use the timestamp. In the EVE JSON output, the value of the timestamp key has been changed to 'timestamp' (instead of 'time'). This allows tools like Splunk to detect the timestamp and use it without configuration. Logstash configuration is simple: input { file { path => [ "/usr/local/var/log/suricata/eve.json" ] codec => json type => "suricata-log" } } filter { if [type] == "suricata-log" { date { match => [ "timestamp", "ISO8601" ] } } } In splunk, auto detection of the fle format is failling and it seems you need to define a type to parse JSON in $SPLUNK_DIR/etc/system/local/props.conf: [suricata] KV_MODE = json NO_BINARY_CHECK = 1 TRUNCATE = 0 Then you can simply declare the log file in $SPLUNK_DIR/etc/system/local/inputs.conf: [monitor:///usr/local/var/log/suricata/eve.json] sourcetype = suricata In both cases the timestamp are correctly imported by the tools.
- Loading branch information
1 parent
1fa4233
commit 6c3c234
Showing
4 changed files
with
19 additions
and
4 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters