No parsing of suricata events when running in offline PCAP modus #33352
Labels
needs_team
Indicates that the issue/PR needs a Team:* label
request-discuss
Label added to request the creator to create a topic in discuss
Stalled
Scenario:
Elastic 7.x / 8.x: when running filebeat / or elastic agent for suricata, there is no mapping/parsing of events in ECS,
If you use suricata in offline PCAP modus, only the last suricata "stats" entry in the eve.json is being mapped.
If you run suricata in live modus, (listening on the network interface) there is no problem with mapping of events.
The text was updated successfully, but these errors were encountered: