To successfully parse Suricata JSON logs via syslog collector we need to
use LUA parser in NetWitness Log Decoder.Suricata LUA parser in this
example is mapping only specific fields from JSON logs to metakeys. In
case additional metakeys needs to be ...