A Snort IDS/IPS dashboard build on Elastisearch, using data parsed from Graylog. Based on template 11191.
Create the Input;
Import the 0. Extractors.json;
Then, It is necessary to create the pipelines in the following order:
- Extract e2Guardian alert fields (optional)
- Extract Snort alert fields (mandatory)
- Extract sshGuard alert fields (mandatory)
- SSH: Extract attempted login remote IP (mandatory)
- GeoIP lookup: dst_addr
- GeoIP lookup: src_addr
Configure the ElasticSearch;
Import the template.