Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

No parsing of suricata events when running in offline PCAP modus #33352

Closed
hsportel opened this issue Oct 14, 2022 · 4 comments
Closed

No parsing of suricata events when running in offline PCAP modus #33352

hsportel opened this issue Oct 14, 2022 · 4 comments
Labels
needs_team Indicates that the issue/PR needs a Team:* label request-discuss Label added to request the creator to create a topic in discuss Stalled

Comments

@hsportel
Copy link

Scenario:

Elastic 7.x / 8.x: when running filebeat / or elastic agent for suricata, there is no mapping/parsing of events in ECS,
If you use suricata in offline PCAP modus, only the last suricata "stats" entry in the eve.json is being mapped.

If you run suricata in live modus, (listening on the network interface) there is no problem with mapping of events.

@botelastic botelastic bot added the needs_team Indicates that the issue/PR needs a Team:* label label Oct 14, 2022
@botelastic
Copy link

botelastic bot commented Oct 14, 2022

This issue doesn't have a Team:<team> label.

@kaiyan-sheng kaiyan-sheng added the request-discuss Label added to request the creator to create a topic in discuss label Nov 28, 2022
@botelastic
Copy link

botelastic bot commented Nov 28, 2022

Thank you very much for creating this issue. However, we would kindly like to ask you to post all questions and issues on the Discuss forum first. In addition to awesome, knowledgeable community contributors, core Beats developers are on the forums every single day to help you out as well. So, your questions will reach a wider audience there, and if we confirm that there is a bug, then you can reopen this issue with the new information or open a new one.

@botelastic
Copy link

botelastic bot commented Nov 28, 2023

Hi!
We just realized that we haven't looked into this issue in a while. We're sorry!

We're labeling this issue as Stale to make it hit our filters and make sure we get back to it as soon as possible. In the meantime, it'd be extremely helpful if you could take a look at it as well and confirm its relevance. A simple comment with a nice emoji will be enough :+1.
Thank you for your contribution!

@botelastic botelastic bot added the Stalled label Nov 28, 2023
@hsportel
Copy link
Author

Is no longer a issue anymore!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
needs_team Indicates that the issue/PR needs a Team:* label request-discuss Label added to request the creator to create a topic in discuss Stalled
Projects
None yet
Development

No branches or pull requests

2 participants