To successfully parse Suricata JSON logs via syslog collector we need to use LUA parser in NetWitness Log Decoder.
Suricata LUA parser in this example is mapping only specific fields from JSON logs to metakeys. In case additional metakeys needs to be mapped then modification of LUA parser is needed and additional "custom" metakeys needs to be added to Concentrator index file.
Process of deploying attached files is following:
RAW reconstruction of event log
Meta Reconstruction of event log
Big thanks to Helmut Wahrmann who helped me developed first JSON lua parser for NW.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.