Project

General

Profile

Feature #10421

suricata unix_stream support for telegraf

Added by Manuel Piovan about 2 months ago.

Status:
New
Priority:
Very Low
Assignee:
-
Category:
Suricata
Target version:
-
Start date:
04/03/2020
Due date:
% Done:

0%

Estimated time:

Description

it would be nice if there was support for telegraf under suricata
input.suricata need unix socket to be created for listening

suricata need
- eve-log:
enabled: yes
filetype: unix_stream
filename: suricata-stats.sock
types:
- stats:
threads: yes

i've made a test and it work if i manually edit the suricata.yaml
more info https://github.com/influxdata/telegraf/tree/master/plugins/inputs/suricata

Immagine.jpg (80.8 KB) Immagine.jpg grafana+suricata example Manuel Piovan, 04/03/2020 10:29 AM

Also available in: Atom PDF