robcowart/synesis_lite_suricata

dashboard present error

vdministrator opened this issue · 6 comments

I used elk7.1 and Kibana dashboard present lot of error after installed synesis_lite_suricata(7.1.x)
.how can I do resolve this problem ?
image

image

image

you can help me !!!

Hi,
This is related to the fact that your index pattern or data is mapped to the wrong template. Probably the default logstash template which is automaticaly created.
Check your logstash pipeline is using the right template and check that is is loaded/installed correctly.
If it does, delete the index data and start over again.
If it doesn't work. Do this:

Stop logstash
Delete the index pattern and the corresponding data (index)
Import the NDJSON again including the index pattern
start logstash again
You should be fine now

Regards

You could also checkout if there are any mapping conflicts

does version 5.x of suricata work with this project! I use Suricata 5 but the problem persists, I delete and add the index, but same problem

how to resolve mapping conflicts, sometimes I find conflict errors

This has not been updated for any Suricata version after 4.x. As I have moved away from Logstash for such projects, I am not planning to update this project. Sorry.