-
Notifications
You must be signed in to change notification settings - Fork 12
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Can't Import the Content Pack #1
Comments
Any movement on this? Its still not working for me. |
Bump?? Anybody home? |
You still stuck on this @JSylvia007? I found a work around for it all. I Never got his package to work but I did manage to do it manually. |
Hey @pipetennathan... I did get it sorted out the same way. It was a bit of a pain but looking through all the logs helped me to figure it out. |
Did you get beats working over TLS? I did. Posted the method here. https://forum.netgate.com/topic/136998/how-to-send-snort-alert-logs-to-graylog-without-barnyard2/11 |
Hi, i meanage to make working content pack for Graylog 3 if some one is still intrasted in it. content-pack-dd56a523-b5e7-402d-a648-f96d771372cd-1.json.txt I can't make Grafana to make some charts, can somebody help me with it? |
How would it be manually? Could you share that solution? We would be very grateful. |
So for Grafana youll need to use their elastic search input and ensure all inputs to it are JSON (which is done with a tickbox in suracata settings in EVE output settings) On the Graylog server you'll need to;
Grafana elastic only cares about JSON. it ignores everything else. Hope this helps. |
Thanks kubala156, I was able to import your revised content pack. But now im stuck on adding the custom Suricata-elastic-template in elasticsearch Brain. In the instructions, it appears he accesses the Elasticsearch GUI. How do I access that? Is it same IP and different port number? Or is it something that is done from the CLI? |
You can do that with Cerebro: https://github.com/lmenezes/cerebro I could import the Content Pack and import the template but I still cannot copy the geo_point fields. Could someone import the templates well? |
Thanks for the assist. I eventually got Cerebro up, but now its giving me an error when trying to import the new template. I just copy and pasted and its giving me an error. |
In this Youtube channel, it explains in a very simple way the installation and configuration of Graylog and Grafana: https://www.youtube.com/channel/UCXPdZsu8g1nKerd-o5A75vA If someone could solve the geo_point issue please let us know. Regards.- |
Howdy! So after the success if the pfSense dashboard that you provided, I figured I would try the Suricata one, especially after what I learned from the pfSense one.
The issue is, I can't get past the content pack piece... I am able to upload it, but I can't apply it. When I try to apply it, I get an error telling me to check the logs. This is an export of the log:
The text was updated successfully, but these errors were encountered: