:ref:`elasticsearch` receives :ref:`nids` alerts from :ref:`suricata` via :ref:`elastic-agent` or :ref:`logstash` and parses them using:
/opt/so/conf/elasticsearch/ingest/suricata.alert/opt/so/conf/elasticsearch/ingest/common.nids/opt/so/conf/elasticsearch/ingest/commonYou can find these online at:
You can find parsed :ref:`nids` alerts in :ref:`alerts`, :ref:`dashboards`, :ref:`hunt`, and :ref:`kibana` via their predefined queries and dashboards or by manually searching for:
event.module:"suricata"event.dataset:"alert"Those alerts should have the following fields:
source.ipsource.portdestination.ipdestination.portnetwork.transportrule.gidrule.namerule.rulerule.revrule.severityrule.uuidrule.version