As a continuation of the article HERE– some more screenshots from the ready to use template….
For the Elasticsearch/Logstash/Kibana users there is a ready to use template that you could download from here – “HTTP-Extended-Custom“
https://github.com/pevma/Suricata-Logstash-Templates
Print
Share
Comment
Cite
Upload
Translate
APA
() » Suricata IDS/IPS – HTTP custom header logging. Retrieved from https://www.truth.cx/2014/08/23/suricata-ids-ips-http-custom-header-logging/.
MLA" » Suricata IDS/IPS – HTTP custom header logging." - , https://www.truth.cx/2014/08/23/suricata-ids-ips-http-custom-header-logging/
HARVARD » Suricata IDS/IPS – HTTP custom header logging., viewed ,
VANCOUVER - » Suricata IDS/IPS – HTTP custom header logging. [Internet]. [Accessed ]. Available from: https://www.truth.cx/2014/08/23/suricata-ids-ips-http-custom-header-logging/
CHICAGO" » Suricata IDS/IPS – HTTP custom header logging." - Accessed . https://www.truth.cx/2014/08/23/suricata-ids-ips-http-custom-header-logging/
IEEE" » Suricata IDS/IPS – HTTP custom header logging." [Online]. Available: https://www.truth.cx/2014/08/23/suricata-ids-ips-http-custom-header-logging/. [Accessed: ]