前提条件
1.Suricata
SURICATA IDS/IPSはネットワーク上の通信を監視し、不審なトラフィックを検知するオープンソースのIDSです。基本的な仕組みはシグネチャ型であるため、あらかじめ設定した不正な通信を検知できます。また、Suricataは検知だけでなく防御も行えることが特徴です。
2.Elasticsearch,Kibana,Filebeat
Elasticsearchをインストール&設定して、Kibana,Filebeatを使用してSURICATAのログを可視化&検索できるようにする
今回はSuricata IDS と ElasticStack を 次のサーバーにインストールします
・1台目サーバー Suricata IDS & Filebeat : openSUSE 16.0 IPアドレス(192.168.11.83)
・2台目サーバー Elasticsearch & kibana : openSUSE 16.0 IPアドレス(192.168.11.85)
1台目サーバー : Suricata インストール
1.Suricata のインストールと設定
①Suricata のインストール
libhiredis1_3_0-1.3.0-1.3.x86_64.rpm libnetfilter_log1-1.0.2-1.14.x86_64.rpm libpcre2-8-0-10.47-1.6.x86_64.rpm
が必要になる場合があります
また、openSUSE16にはSuricataの公式リポジトリーがありませんのでTumbleweedのリポジトリーを利用します。
# zypper addrepo https://download.opensuse.org/repositories/server:monitoring/openSUSE_Tumbleweed/server:monitoring.repo
# zypper refresh
# zypper -n install suricata
バージョンチェック
# suricata -V
his is Suricata version 8.0.6 RELEASE
②Suricataがネットワークパケットを検査するインターフェースとIPアドレスを決定
# ip --brief add
lo UNKNOWN 127.0.0.1/8 ::1/128
ens33 UP 192.168.11.83/24 fe80::20c:29ff:fe2e:4273/64
③設定ファイルを編集
# vi /etc/suricata/suricata.yaml
18行目 : コメントアウトしてその下に追加(varsセクションで、ネットワークを定義する)
#HOME_NET: "[192.168.0.0/16,10.0.0.0/8,172.16.0.0/12]"
HOME_NET: "[192.168.11.0/24]"
158行目あたり : 変更
community-id: false → community-id: true
661行目あたり : af-packetセクションのインターフェース名を設定
af-packet:
- interface: ens33
# vi /etc/sysconfig/suricata
# 9行目 :インターフェイスを変更
SURICATA_OPTIONS="-c /etc/suricata/suricata.yaml -i ens33"
④ディレクトリのグループと権限の設定
/etc/suricata、 /var/lib/suricata、/var/log/suricata をsuricataグループにし、読み書き権限を設定します。
⑤Suricataのルール更新
# suricata-update
⑥Suricataの起動
# systemctl start suricata
# systemctl enable --now suricata
Created symlink '/etc/systemd/system/multi-user.target.wants/suricata.service' → '/usr/lib/systemd/system/suricata.service'.
⑦Suricataの起動確認
# systemctl status suricata
● suricata.service - Suricata Intrusion Detection and Prevention Tool
Loaded: loaded (/usr/lib/systemd/system/suricata.service; enabled; preset: disabled)
Active: active (running) since Sat 2026-08-15 09:29:55 JST; 35s ago
Invocation: 8032f64986724063a07ad7ea7222d51b
Docs: man:suricata(1)
Main PID: 32083 (Suricata-Main)
Tasks: 8 (limit: 4565)
CPU: 413ms
CGroup: /system.slice/suricata.service
mq32083 /usr/bin/suricata -c /etc/suricata/suricata.yaml -i ens33
Aug 15 09:29:55 Lepard systemd[1]: Started Suricata Intrusion Detection and Prevention Tool.
Aug 15 09:29:55 Lepard suricata[32083]: i: suricata: This is Suricata version 8.0.6 RELEASE running in SYSTEM mode
Aug 15 09:29:55 Lepard suricata[32083]: W: detect: No rule files match the pattern /var/lib/suricata/rules/suricata.rules
Aug 15 09:29:55 Lepard suricata[32083]: W: detect: 1 rule files specified, but no rules were loaded!
Aug 15 09:29:55 Lepard suricata[32083]: W: mpm-hs: Failed to create Hyperscan cache folder, make sure the parent folder is writeable or adjust sgh-mpm-caching-pa>
Aug 15 09:29:55 Lepard suricata[32083]: i: threads: Threads created -> W: 2 FM: 1 FR: 1 Engine started.
ログを確認
# tail /var/log/suricata/suricata.log
[32083 - Suricata-Main] 2026-08-15 09:29:55 Info: logopenfile: stats output device (regular) initialized: stats.log
[32083 - Suricata-Main] 2026-08-15 09:29:55 Warning: detect: No rule files match the pattern /var/lib/suricata/rules/suricata.rules
[32083 - Suricata-Main] 2026-08-15 09:29:55 Warning: detect: 1 rule files specified, but no rules were loaded!
[32083 - Suricata-Main] 2026-08-15 09:29:55 Info: threshold-config: Threshold config parsed: 0 rule(s) found
[32083 - Suricata-Main] 2026-08-15 09:29:55 Info: detect: 0 signatures processed. 0 are IP-only rules, 0 are inspecting packet payload, 0 inspect application layer, 0 are decoder event only
[32083 - Suricata-Main] 2026-08-15 09:29:55 Warning: mpm-hs: Failed to create Hyperscan cache folder, make sure the parent folder is writeable or adjust sgh-mpm-caching-path setting (/var/lib/suricata/cache/sgh)
[32083 - Suricata-Main] 2026-08-15 09:29:55 Info: unix-manager: unix socket '/var/run/suricata/suricata-command.socket'
[32083 - Suricata-Main] 2026-08-15 09:29:55 Info: runmodes: ens33: creating 2 threads
[32088 - W#01-ens33] 2026-08-15 09:29:55 Info: ioctl: ens33: MTU 1500
[32083 - Suricata-Main] 2026-08-15 09:29:55 Notice: threads: Threads created -> W: 2 FM: 1 FR: 1 Engine started.
統計情報を確認するには、stats.log ファイルを確認します(デフォルトで8秒ごとに更新)
# tail -f /var/log/suricata/stats.log
より高度な出力であるEVE JSONは、以下のコマンドで生成することができる
# tail -f /var/log/suricata/eve.json
2.Suricata のテスト
①curl ユーティリティで ping テストを実行
# curl http://testmynids.org/uid/index.html
uid=0(root) gid=0(root) groups=0(root)
②指定されたルール番号を使用してログファイルを確認する
Suricataには、デフォルトで有効になっている次の2つのログファイルが付属しています。
/var/log/suricata/fast.log
/var/log/suricata/eve.log
curlリクエストに対応するログエントリーを確認するために、/var/log/suricata/fast.log ログファイルをgrepコマンドを使用してチェックします。2100498 ルール識別子を使用してログエントリーを検索します。(IPv4の場合)
# grep 2100498 /var/log/suricata/fast.log
08/15/2026-10:03:11.329557 [**] [1:2100498:7] GPL ATTACK_RESPONSE id check returned root [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 13.227.50.49:80 -> 192.168.11.83:51984
③/var/log/suricata/eve.log のイベント確認
jq をインストール
# zypper -n install jq
2100498シグネチャを検索して、EVEログのイベントをフィルタリング
2100498の値と一致するsignature_idキーを持つalertオブジェクトを表示
# jq 'select(.alert .signature_id==2100498)' /var/log/suricata/eve.json
{
"timestamp": "2026-08-15T10:03:11.329557+0900",
"flow_id": 2178014284648023,
"in_iface": "ens33",
"event_type": "alert",
"src_ip": "13.227.50.49",
"src_port": 80,
"dest_ip": "192.168.11.83",
"dest_port": 51984,
"proto": "TCP",
"ip_v": 4,
"pkt_src": "wire/pcap",
"community_id": "1:E0TNc7rSm81EU3CHdkJKObWI380=",
"alert": {
"action": "allowed",
"gid": 1,
"signature_id": 2100498,
"rev": 7,
"signature": "GPL ATTACK_RESPONSE id check returned root",
"category": "Potentially Bad Traffic",
"severity": 2,
"metadata": {
"confidence": [
"Medium"
],
"created_at": [
"2010_09_23"
],
"signature_severity": [
"Informational"
],
"updated_at": [
"2019_07_26"
]
}
},
"app_proto": "http",
"direction": "to_client",
"flow": {
"pkts_toserver": 6,
"pkts_toclient": 5,
"bytes_toserver": 496,
"bytes_toclient": 876,
"start": "2026-08-15T10:03:11.310500+0900",
"src_ip": "192.168.11.83",
"dest_ip": "13.227.50.49",
"src_port": 51984,
"dest_port": 80
}
}
3.Suricata Rulesの設定
①Suricataにパッケージされているルールセットの表示
# ls -al /var/lib/suricata/rules/
total 44116
drwxrwx--- 1 root suricata 70 Aug 15 10:01 .
drwxr-x--- 1 suricata suricata 32 Aug 15 09:25 ..
-rw-rw-r-- 1 root suricata 3228 Aug 15 10:01 classification.config
-rw-r--r-- 1 root root 45167101 Aug 15 10:01 suricata.rules
②ルールセットを提供するソースのインデックス一覧
# suricata-update list-sources
Name: et/open
Vendor: Proofpoint
Summary: Emerging Threats Open Ruleset
License: MIT
Name: et/pro
Vendor: Proofpoint
Summary: Emerging Threats Pro Ruleset
License: Commercial
Replaces: et/open
Parameters: secret-code
Subscription: https://www.proofpoint.com/us/threat-insight/et-pro-ruleset
Name: oisf/trafficid
Vendor: OISF
Summary: Suricata Traffic ID ruleset
License: MIT
Name: scwx/enhanced
Vendor: Secureworks
Summary: Secureworks suricata-enhanced ruleset
License: Commercial
Parameters: secret-code
Subscription: https://www.secureworks.com/contact/ (Please reference CTU Countermeasures)
Name: scwx/malware
Vendor: Secureworks
Summary: Secureworks suricata-malware ruleset
License: Commercial
Parameters: secret-code
Subscription: https://www.secureworks.com/contact/ (Please reference CTU Countermeasures)
Name: scwx/security
Vendor: Secureworks
Summary: Secureworks suricata-security ruleset
License: Commercial
Parameters: secret-code
Subscription: https://www.secureworks.com/contact/ (Please reference CTU Countermeasures)
Name: abuse.ch/sslbl-blacklist
Vendor: Abuse.ch
Summary: Abuse.ch SSL Blacklist
License: CC0-1.0
Replaces: sslbl/ssl-fp-blacklist
Name: abuse.ch/sslbl-ja3
Vendor: Abuse.ch
Summary: Abuse.ch Suricata JA3 Fingerprint Ruleset
License: CC0-1.0
Replaces: sslbl/ja3-fingerprints
Name: abuse.ch/feodotracker
Vendor: Abuse.ch
Summary: Abuse.ch Feodo Tracker Botnet C2 IP ruleset
License: CC0-1.0
Name: abuse.ch/urlhaus
Vendor: abuse.ch
Summary: Abuse.ch URLhaus Suricata Rules
License: CC0-1.0
Name: etnetera/aggressive
Vendor: Etnetera a.s.
Summary: Etnetera aggressive IP blacklist
License: MIT
Name: tgreen/hunting
Vendor: tgreen
Summary: Threat hunting rules
License: GPLv3
Name: stamus/lateral
Vendor: Stamus Networks
Summary: Lateral movement rules
License: GPL-3.0-only
Name: stamus/nrd-30-open
Vendor: Stamus Networks
Summary: Newly Registered Domains Open only - 30 day list, complete
License: Commercial
Parameters: secret-code
Subscription: https://www.stamus-networks.com/stamus-labs/subscribe-to-threat-intel-feed
Name: stamus/nrd-14-open
Vendor: Stamus Networks
Summary: Newly Registered Domains Open only - 14 day list, complete
License: Commercial
Parameters: secret-code
Subscription: https://www.stamus-networks.com/stamus-labs/subscribe-to-threat-intel-feed
Name: stamus/nrd-entropy-30-open
Vendor: Stamus Networks
Summary: Newly Registered Domains Open only - 30 day list, high entropy
License: Commercial
Parameters: secret-code
Subscription: https://www.stamus-networks.com/stamus-labs/subscribe-to-threat-intel-feed
Name: stamus/nrd-entropy-14-open
Vendor: Stamus Networks
Summary: Newly Registered Domains Open only - 14 day list, high entropy
License: Commercial
Parameters: secret-code
Subscription: https://www.stamus-networks.com/stamus-labs/subscribe-to-threat-intel-feed
Name: stamus/nrd-phishing-30-open
Vendor: Stamus Networks
Summary: Newly Registered Domains Open only - 30 day list, phishing
License: Commercial
Parameters: secret-code
Subscription: https://www.stamus-networks.com/stamus-labs/subscribe-to-threat-intel-feed
Name: stamus/nrd-phishing-14-open
Vendor: Stamus Networks
Summary: Newly Registered Domains Open only - 14 day list, phishing
License: Commercial
Parameters: secret-code
Subscription: https://www.stamus-networks.com/stamus-labs/subscribe-to-threat-intel-feed
Name: pawpatrules
Vendor: pawpatrules
Summary: PAW Patrules is a collection of rules for IDPS / NSM Suricata engine
License: CC-BY-SA-4.0
Name: ptrules/open
Vendor: Positive Technologies
Summary: Positive Technologies Open Ruleset
License: Custom
Name: aleksibovellan/nmap
Vendor: aleksibovellan
Summary: Suricata IDS/IPS Detection Rules Against NMAP Scans
License: MIT
Name: ipfire/dbl
Vendor: IPFire
Summary: IPFire DBL
License: CC-BY-SA-4.0
Name: julioliraup/antiphishing
Vendor: julioliraup
Summary: Antiphishing for protection against phishing attacks
License: GPL-3.0
Name: the-hunters-ledger/open
Vendor: The Hunters Ledger
Summary: The Hunters Ledger threat-intelligence detection feed
License: CC-BY-4.0
③ソースを有効にする(tgreen/huntingを有効にする場合)
# suricata-update enable-source tgreen/hunting
15/8/2026 -- 10:26:00 - <Info> -- Using data-directory /var/lib/suricata.
15/8/2026 -- 10:26:00 - <Info> -- Using Suricata configuration /etc/suricata/suricata.yaml
15/8/2026 -- 10:26:00 - <Info> -- Using /usr/share/suricata/rules for Suricata provided rules.
15/8/2026 -- 10:26:00 - <Info> -- Found Suricata version 8.0.6 at /usr/bin/suricata.
15/8/2026 -- 10:26:00 - <Info> -- Creating directory /var/lib/suricata/update/sources
15/8/2026 -- 10:26:00 - <Info> -- Enabling default source et/open
15/8/2026 -- 10:26:00 - <Info> -- Source tgreen/hunting enabled
アップデートを実行
# suricata-update update-sources
Suricata service再起動
# systemctl restart suricata
4.Suricata Custom Rulesの作成
①カスタマールールを含むファイルを作成
# vi /var/lib/suricata/rules/local.rules
下記内容を記載
alert icmp any any -> any any (msg:"ICMP Ping"; sid:100000; rev:1;)
②設定ファイルを編集(新しいルールのパスを定義)
# vi /etc/suricata/suricata.yaml
# 2332行目あたりに追記
default-rule-path: /var/lib/suricata/rules
rule-files:
- suricata.rules
- local.rules
③設定ファイルのテスト
# suricata -T -c /etc/suricata/suricata.yaml -v
Notice: suricata: This is Suricata version 8.0.6 RELEASE running in SYSTEM mode
Info: cpu: CPUs/cores online: 2
Info: suricata: Running suricata under test mode
Info: suricata: Setting engine mode to IDS mode by default
Info: exception-policy: master exception-policy set to: auto
Info: logopenfile: fast output device (regular) initialized: fast.log
Info: logopenfile: eve-log output device (regular) initialized: eve.json
Info: logopenfile: stats output device (regular) initialized: stats.log
Info: detect: 2 rule files processed. 52312 rules successfully loaded, 0 rules failed, 0 rules skipped
Info: threshold-config: Threshold config parsed: 0 rule(s) found
Info: detect: 52317 signatures processed. 1268 are IP-only rules, 4511 are inspecting packet payload, 46302 inspect application layer, 110 are decoder event only
Notice: suricata: Configuration provided was successfully loaded. Exiting.
Suricat service再起動
# systemctl restart suricata
④Custom Rulesの適用テスト
同一ローカルネットワーク上の別のデバイスでpingを実行し、ログに記録されたかどうかを確認する
# cat /var/log/suricata/fast.log
08/15/2026-10:29:55.626037 [**] [1:100000:1] ICMP Ping [**] [Classification: (null)] [Priority: 3] {ICMP} 192.168.11.14:8 -> 192.168.11.83:0
08/15/2026-10:29:55.626081 [**] [1:100000:1] ICMP Ping [**] [Classification: (null)] [Priority: 3] {ICMP} 192.168.11.83:0 -> 192.168.11.14:0
JSON形式のログを取得するには下記コマンドを実行し、同一ローカルネットワーク上の別のデバイスでpingを実行する
# tail -f /var/log/suricata/eve.json | jq 'select(.event_type=="alert")'
pingを実行するとコンソールに下記のように表示される
{
"timestamp": "2026-08-15T10:34:15.334142+0900",
"in_iface": "ens33",
"event_type": "alert",
"src_ip": "192.168.11.83",
"dest_ip": "138.197.124.163",
"proto": "ICMP",
"ip_v": 4,
"icmp_type": 3,
"icmp_code": 13,
"pkt_src": "wire/pcap",
"alert": {
"action": "allowed",
"gid": 1,
"signature_id": 100000,
"rev": 1,
"signature": "ICMP Ping",
"category": "",
"severity": 3
}
}
{
"timestamp": "2026-08-15T10:34:15.832446+0900",
"in_iface": "ens33",
"event_type": "alert",
"pkt_src": "wire/pcap",
"alert": {
"action": "allowed",
"gid": 1,
"signature_id": 2200121,
"rev": 1,
"signature": "SURICATA Ethertype unknown",
"category": "Generic Protocol Command Decode",
"severity": 3
}
}
5. SuricataをIPSに設定する
悪意のあるネットワーク・トラフィックをドロップするようにSuricataをIPSモードで起動するように設定する
①SURICATAの/etc/sysconfig/suricata設定ファイルを編集する
# vi /etc/sysconfig/suricata
9行目 : コメントにして、その下に追加(SURICATAにIPSモードで実行するように指示する)
#SURICATA_OPTIONS="-c /etc/suricata/suricata.yaml -i ens33"
SURICATA_OPTIONS="-c /etc/suricata/suricata.yaml -q 0 -vvv "
➁Suricataを再起動
# systemctl daemon-reload
# systemctl restart suricata.service
ステータス確認
# systemctl status suricata.service
● suricata.service - Suricata Intrusion Detection and Prevention Tool
Loaded: loaded (/usr/lib/systemd/system/suricata.service; enabled; preset: disabled)
Active: active (running) since Sat 2026-08-15 10:36:25 JST; 26s ago
Invocation: 3f4b79e1539c422ab5b5989431cf4740
Docs: man:suricata(1)
Main PID: 16670 (Suricata-Main)
Tasks: 10 (limit: 4565)
CPU: 17.944s
CGroup: /system.slice/suricata.service
mq16670 /usr/bin/suricata -c /etc/suricata/suricata.yaml -q 0 -vvv
Aug 15 10:36:43 Lepard suricata[16670]: [16670] Perf: mpm-hs-cache: rule group caching - loaded: 117 newly cached: 0 total cacheable: 117
Aug 15 10:36:43 Lepard suricata[16670]: [16670] Info: unix-manager: unix socket '/var/run/suricata/suricata-command.socket'
Aug 15 10:36:43 Lepard suricata[16670]: [16670] Config: tmqh-flow: AutoFP mode using "Hash" flow load balancer
Aug 15 10:36:43 Lepard suricata[16670]: [16679] Info: nfq: binding this thread 0 to queue '0'
Aug 15 10:36:43 Lepard suricata[16670]: [16679] Info: nfq: setting queue length to 4096
Aug 15 10:36:43 Lepard suricata[16670]: [16679] Info: nfq: setting nfnl bufsize to 6144000
Aug 15 10:36:43 Lepard suricata[16670]: [16670] Config: flow-manager: using 1 flow manager threads
Aug 15 10:36:43 Lepard suricata[16670]: [16670] Config: flow-manager: using 1 flow recycler threads
Aug 15 10:36:43 Lepard suricata[16670]: [16670] Config: log-flush: log flusher thread not used with heartbeat.output-flush-interval of 0
Aug 15 10:36:43 Lepard suricata[16670]: [16670] Notice: threads: Threads created -> RX: 1 W: 2 TX: 1 FM: 1 FR: 1 Engine started.
➂入ってくるネットワーク・トラフィックをSuricataのNFQUEUEに向ける
Firewalld がインストールされ、有効になっているのでSuricataに必要なルールをFirewalldに追加する(SSHポートは22と仮定する)
# firewall-cmd --permanent --direct --add-rule ipv4 filter INPUT 0 -p tcp --dport 22 -j NFQUEUE --queue-bypass
# firewall-cmd --permanent --direct --add-rule ipv4 filter OUTPUT 0 -p tcp --sport 22 -j NFQUEUE --queue-bypass
FORWARDルールを追加して、サーバーが他のシステムのゲートウェイとして動作している場合、そのトラフィックもすべてSURICATAに行って処理されるようにします。
# firewall-cmd --permanent --direct --add-rule ipv4 filter FORWARD 0 -j NFQUEUE
# firewall-cmd --permanent --direct --add-rule ipv6 filter FORWARD 0 -j NFQUEUE
最後の2つのINPUTとOUTPUTルールは、SSHトラフィックでない残りのトラフィックをすべてSuricataに送って処理させる。
# firewall-cmd --permanent --direct --add-rule ipv4 filter INPUT 1 -j NFQUEUE
# firewall-cmd --permanent --direct --add-rule ipv4 filter OUTPUT 1 -j NFQUEUE
IPv6も同様にする
# firewall-cmd --permanent --direct --add-rule ipv6 filter INPUT 1 -j NFQUEUE
# firewall-cmd --permanent --direct --add-rule ipv6 filter OUTPUT 1 -j NFQUEUE
Firewalldをリロード
# firewall-cmd --reload
※openSUSEで firewall-cmd --direct を使って NFQUEUE を設定しても有効にならない場合があります、これはfirewalld のバックエンドが nftables になっているため、従来のiptablesベースのダイレクトルールが正しくフックされないのでバックエンドを iptables に変更します
# vi /etc/firewalld/firewalld.conf
59行目 : 変更
FirewallBackend=iptables
firewalld を再起動
# systemctl restart firewalld
④SURICATA がトラフィックを正しくドロップしていることを確認
シグネチャのデフォルトアクションをalertやlogからactive dropping trafficに切り替える
/var/lib/suricata/rules/suricata.rulesファイルを開き、sid:2100498に該当するものがあれば コメントアウトする
# vi /var/lib/suricata/rules/suricata.rules
#alert ip any any -> any any (msg:"GPL ATTACK_RESPONSE id check returned root"; content:"uid=0|28|root|29|"; classtype:bad-unknown; sid:2100498; rev:7; metadata:created_at 2010_09_23, confidence Medium, signature_severity Informational, updated_at 2019_07_26;)
/var/lib/suricata/rules/local.rulesにsid:2100498として新規作成する
# vi /var/lib/suricata/rules/local.rules
drop ip any any -> any any (msg:"GPL ATTACK_RESPONSE id check returned root"; content:"uid=0|28|root|29|"; classtype:bad-unknown; sid:2100498; rev:7; metadata:created_at 2010_09_23, confidence Medium, signature_severity Informational, updated_at 2019_07_26;)
⑤suricata再起動
# systemctl restart suricata
⑥curlを使ってこのルールをテスト
# curl --max-time 5 http://testmynids.org/uid/index.html
curl: (28) Operation timed out after 5001 milliseconds with 0 out of 39 bytes received
jqを使ってeve.logファイルを調べる
# jq 'select(.alert .signature_id==2100498)' /var/log/suricata/eve.json
{
"timestamp": "2026-08-15T12:04:33.403078+0900",
"flow_id": 540462793448580,
"event_type": "alert",
"src_ip": "13.227.50.46",
"src_port": 80,
"dest_ip": "192.168.11.83",
"dest_port": 50352,
"proto": "TCP",
"ip_v": 4,
"pkt_src": "wire/pcap",
"community_id": "1:4XWnzbezg/hTJzsabY5QXUej/cM=",
"alert": {
"action": "blocked",
"gid": 1,
"signature_id": 2100498,
"rev": 7,
"signature": "GPL ATTACK_RESPONSE id check returned root",
"category": "Potentially Bad Traffic",
"severity": 2,
"metadata": {
"confidence": [
"Medium"
],
"created_at": [
"2010_09_23"
],
"signature_severity": [
"Informational"
],
"updated_at": [
"2019_07_26"
]
}
},
"app_proto": "http",
"direction": "to_client",
"flow": {
"pkts_toserver": 4,
"pkts_toclient": 4,
"bytes_toserver": 308,
"bytes_toclient": 754,
"start": "2026-08-15T12:04:33.387980+0900",
"src_ip": "192.168.11.83",
"dest_ip": "13.227.50.46",
"src_port": 50352,
"dest_port": 80
}
}
"action": "blocked",になっている
ELK StackとSURICATAの統合
Elastic Stackをインストール&設定して、SURICATAのログをより効率的に可視化&検索できるようにする
本セクションは2台目のopenSUSE16.0サーバーで行います
1. Elasticsearchのインストール
1.1 リポジトリ定義を/etc/zypp/repos.d ディレクトリに作成
# vi /etc/zypp/repos.d/elasticsearch.repo
下記内容記述
[elasticsearch-9.x]
name=Elasticsearch repository for 9.x packages
baseurl=https://artifacts.elastic.co/packages/9.x/yum
gpgcheck=1
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch
enabled=1
autorefresh=1
type=rpm-md
1.2 Elasticsearch インストール
# zypper refresh
# zypper -n install elasticsearch
2. Elasticsearch 設定
Elasticsearchはデフォルトでローカル接続のみを受け付けるように設定されています。また、認証が有効になっていないため、Filebeatなどのツールはログを送信できません。今回は、Elasticsearchのネットワーク設定を行い、Elasticsearchに組み込まれているxpackセキュリティモジュールを有効にします。
2.1 Elasticsearchネットワークの設定
ElasticsearchとSURICATAのサーバは別々なので、Elasticsearchがプライベートネットワークインターフェースで接続をリッスンするように設定する必要がある
# vi /etc/elasticsearch/elasticsearch.yml
57行目 : Elasticsearch serverのローカルアドレス追加
#network.host: 192.168.0.1
network.host: 192.168.11.85
62行目コメント解除
http.port: 9200
2.2 Elasticsearch を起動
# systemctl daemon-reload
# systemctl enable elasticsearch.service
# systemctl start elasticsearch.service
2.3 elasticとkibana_systemのパスワードを作成
elasticユーザとkibana_systemユーザのパスワードは後で使用するので必ずコピーしておく
kibana_systemユーザはKibanaの設定に使用する
elasticユーザはFilebeat、Auditbeatの設定およびKibanaへのログインに使用する
パスワードを忘れた場合は、再度コマンドを使用してパスワードをリセットできます。
[elastic] userのパスワード作成
# cd /usr/share/elasticsearch/bin
# ./elasticsearch-reset-password -u elastic
This tool will reset the password of the [elastic] user to an autogenerated value.
The password will be printed in the console.
Please confirm that you would like to continue [y/N]y
Password for the [elastic] user successfully reset.
New value: =mmPZ8dBBP3-S5Cw-Xl2
※Elasticsearch パスワードのリセット
自動生成されたElasticユーザーパスワードが複雑すぎるので、/usr/share/elasticsearch/bin/elasticsearch-reset-passwordコマンドを使ってリセットできます
パスワードをリセットするには、コマンドを実行する
# /usr/share/elasticsearch/bin/elasticsearch-reset-password -u elastic -i
This tool will reset the password of the [elastic] user.
You will be prompted to enter the password.
Please confirm that you would like to continue [y/N]y
Enter password for [elastic]:
Re-enter password for [elastic]:
Password for the [elastic] user successfully reset.
[kibana_system]userのパスワード作成
# cd /usr/share/elasticsearch/bin
# ./elasticsearch-reset-password -u kibana_system
This tool will reset the password of the [kibana_system] user to an autogenerated value.
The password will be printed in the console.
Please confirm that you would like to continue [y/N]y
Password for the [kibana_system] user successfully reset.
New value: key1k=BcAu5YmiTfw*tg
3. Kibana のインストールと設定
本セクションは2台目のopebSUSE16.0 サーバーで行います
3.1 Kibanaインストール
# zypper -n install kibana
3.2 xpackセキュリティモジュールの設定
Kibana の xpack セキュリティ機能を有効にして、Kibana が Elasticsearch にデータを保存するために使用するいくつかの暗号化キーを作成する。
暗号化キーは、/usr/share/kibana/bin ディレクトリに含まれる kibana-encryption-keys ユーティリティを使用して作成する。
作成した3つのキーを安全な場所に保存しておく
# cd /usr/share/kibana/bin/
# ./kibana-encryption-keys generate -q --force
xpack.encryptedSavedObjects.encryptionKey: 05d9c293050ed853fcad3a9c546fd1c5e9b1df3e73a38108292cbba2f83f0330
xpack.reporting.encryptionKey: 1560d869961203f4bc1395c62eb1f32c5c3df2fe03010d3924ec1f33e190a0af
xpack.security.encryptionKey: 99234650517ec523e570b2542360d5c59b61adfcba0c444059a559b54e1373ad
これらのキーをKibanaの/etc/kibana/kibana.yml設定ファイルに追加する
# vi /etc/kibana/kibana.yml
最終行に記述
xpack.encryptedSavedObjects.encryptionKey: 05d9c293050ed853fcad3a9c546fd1c5e9b1df3e73a38108292cbba2f83f0330
xpack.reporting.encryptionKey: 1560d869961203f4bc1395c62eb1f32c5c3df2fe03010d3924ec1f33e190a0af
xpack.security.encryptionKey: 99234650517ec523e570b2542360d5c59b61adfcba0c444059a559b54e1373ad
3.3 Kibana ネットワークの設定
# vi /etc/kibana/kibana.yml
6行目 : コメント解除
server.port: 5601
12行目 : サーバーのプライベートIPアドレス(192.168.11.85)を追加
#server.host: "localhost"
server.host: "192.168.11.85"
3.4 Kibana-Elasticsearch Enrollment Token の生成
Kibana インスタンスを、セキュリティ機能が有効になっている既存の Elasticsearch クラスタと通信するように設定するには、登録トークンが必要です。Kibana 用の Enrollment Token は以下のコマンドで生成できる
# /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s kibana
eyJ2ZXIiOiI4LjE0LjAiLCJhZHIiOlsiMTkyLjE2OC4xMS44NTo5MjAwIl0sImZnciI6IjQ3ODI0NTU2MzY2MTJjMDk1ZmU3ODJjNmYzNmJkMmRmMjg3MzU0ZjQxMmE1NDk2MTYzZjgzNjMwZGZhNTkzOGUiLCJrZXkiOiI4WWV1QTZBQkhsN2FYSHFVSVZ5XzpwaU4wRmVkaWRsbGs5XzAyWk9PUHhnIn0=
3.5 Kibanaの起動
Kibana 9 を起動し、システム起動時に実行できるようにする。
# systemctl enable --now kibana
# systemctl start kibana
ステータス確認
# systemctl status kibana
● kibana.service - Kibana
Loaded: loaded (/usr/lib/systemd/system/kibana.service; enabled; preset: disabled)
Active: active (running) since Sat 2026-08-15 13:29:19 JST; 40s ago
Invocation: 08dc0af732844a56b9929cd6dbff3746
Docs: https://www.elastic.co
Main PID: 7714 (MainThread)
Tasks: 11 (limit: 4565)
CPU: 15.038s
CGroup: /system.slice/kibana.service
mq7714 /usr/share/kibana/bin/../node/default/bin/node /usr/share/kibana/bin/../node_modules/@kbn/cli/kibana/dist
Aug 15 13:29:22 Lion kibana[7714]: Native global console methods have been overridden in production environment.
Aug 15 13:29:23 Lion kibana[7714]: [2026-08-15T13:29:23.923+09:00][INFO ][root] Kibana is starting
Aug 15 13:29:24 Lion kibana[7714]: [2026-08-15T13:29:24.026+09:00][INFO ][node] Kibana process configured with roles: [background_tasks, ui]
Aug 15 13:29:33 Lion kibana[7714]: [2026-08-15T13:29:33.588+09:00][INFO ][plugins-service] The following plugins are disabled: "cloudChat,cloudExperiments,cloudFullStory,dataFe>
Aug 15 13:29:33 Lion kibana[7714]: [2026-08-15T13:29:33.661+09:00][INFO ][http.server.Preboot] http server running at http://192.168.11.85:5601
Aug 15 13:29:33 Lion kibana[7714]: [2026-08-15T13:29:33.924+09:00][INFO ][plugins-system.preboot] Setting up [1] plugins: [interactiveSetup]
Aug 15 13:29:33 Lion kibana[7714]: [2026-08-15T13:29:33.943+09:00][INFO ][preboot] "interactiveSetup" plugin is holding setup: Validating Elasticsearch connection configuration …
Aug 15 13:29:33 Lion kibana[7714]: [2026-08-15T13:29:33.979+09:00][INFO ][root] Holding setup until preboot stage is completed.
Aug 15 13:29:41 Lion kibana[7714]: i Kibana has not been configured.
Aug 15 13:29:41 Lion kibana[7714]: Go to http://192.168.11.85:5601/?code=694664 to get started.
出力の最後のほうに以下のように表示される
Go to http://192.168.11.85:5601/?code=694664 to get started.
提供されたKibanaのURL(codeを含む)をコピーしてブラウザで使用し、Kibanaにアクセスしてセットアップを完了する。
4. Kibana9 ダッシュボードにアクセスする
Firewallが起動している場合は、Kibanaポートを開く
# firewall-cmd --add-port=5601/tcp --permanent
# firewall-cmd --reload
http://192.168.11.85:5601/?code=694664にアクセスする
(各自の適切なアドレスをコピー)
Kibana 9にアクセスすると、ウェルカムページでElasticの設定を求められます。
最初に、生成した登録トークンを入力する。
/usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s kibana, コマンドを使用して生成された Kibana トークンをコピーし、ボックスに貼り付ける

トークンをペーストすると、Kibana が自動的に Elasticsearch に接続します。
Configure Elastic をクリックします。設定が保存され、Elasticsearch が設定、再起動されます。

ログインページに移動します。生成されたElasticユーザー認証情報を使用してログインします。
Username : elastic
Password : わかりやすく再生成したパスワード

ウェルカムページで、「Explore on my own」をクリックしてKibana 9.xダッシュボードに進む。


elasticスーパーユーザーアカウントを使う必要がないように、新しいユーザーアカウントを作成します。
メインメニューを開き、Stack Management >Security> Users

右上の"Create user"ボタンをクリック

新規ユーザー情報を入力し、Privilegesでkibana_admin、kibana_system、monitoring_user、editorのロールを割り当てる
最後に[Create user]をクリックする
現在のプロファイルからログアウトし、新しく作成したユーザーアカウントでログインできることを確認する。現在、SURICATAのホストでFilebeatとAuditbeatを設定していないため、Kibanaで表示できるデータがありません。
SURICATAサーバにFilebeatをインストール
本作業はSuricataをインストールした1台目のopenSUSE16.0 サーバーで作業する
1. Filebeat インストール
1.1 リポジトリ定義を/etc/zypp/repos.d/ ディレクトリに作成
# vi /etc/zypp/repos.d/elasticsearch.repo
下記内容記述
[elasticsearch-9.x]
name=Elasticsearch repository for 9.x packages
baseurl=https://artifacts.elastic.co/packages/9.x/yum
gpgcheck=1
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch
enabled=1
autorefresh=1
type=rpm-md
1.2 Filebeatをインストール
# zypper refresh
# zypper -n install filebeat
1.3 Elasticsearch CA証明書作成
Elasticsearch CA証明書をダウンロードし、任意のディレクトリに保存します(今回は/etc/filebeat/elastic-ca.crtとして保存します)
(openssl導入済みとする)
※第2サーバー(Elasticsearchを導入したサーバー)で9200ポートを開放しておく
# openssl s_client -connect 192.168.11.85:9200 \
-showcerts </dev/null 2>/dev/null | \
openssl x509 -outform PEM > /etc/filebeat/elastic-ca.crt
1.4 FilebeatをElasticsearchとKibanaに接続するように設定
# vi /etc/filebeat/filebeat.yml
137行目 : KibanaインスタンスのプライベートIPアドレスとポートを指す行を追加する
#host: "localhost:5601"
host: "192.168.11.85:5601"
164行目 : コメントアウト
#hosts: ["localhost:9200"]
165行目 : Elasticsearch のipアドレスとelasticsearchのポート番号を入力
hosts: ["https://192.168.11.85:9200"]
171行目 : コメント解除
protocol: "https"
172行目 : Elasticsearch CA証明書指定
ssl.certificate_authorities: ["/etc/filebeat/elastic-ca.crt"]
175,176行目コメント解除し、[username]はデフォルトのままにし、[password]は[elastic]ユーザーのパスワードを入力する
username: "elastic"
password: “xxxxxxxxx"
1.5 設定ファイルテスト
# filebeat test config
Config OK
1.6 Filebeatsの組み込みSuricataモジュールを有効にする
# filebeat modules enable suricata
上記コマンドにより /etc/filebeat/modules.d/suricata.yml.disabled が/etc/filebeat/modules.d/suricata.yml になりますが内容は変化しませんので以下のように編集します
# vi /etc/filebeat/modules.d/suricata.yml
6-7行目 : 下記のとおり変更
eve:
enabled: true
var.paths: ["/var/log/suricata/eve.json"]
1.7 初期環境をセットアップ
Suricataサービスにpipeline
SIEMダッシュボードをElasticsearchにロードします
# filebeat setup -e
-----------------------------------------------------------------------------------------------------------------------------------------
{"log.level":"info","@timestamp":"2026-08-15T13:50:14.673+0900","log.logger":"modules","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/fileset.LoadPipeline","file.name":"fileset/pipelines.go","file.line":134},"message":"Elasticsearch pipeline loaded.","service.name":"filebeat","pipeline":"filebeat-9.5.1-suricata-eve-pipeline","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2026-08-15T13:50:14.744+0900","log.logger":"modules","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/fileset.LoadPipeline","file.name":"fileset/pipelines.go","file.line":134},"message":"Elasticsearch pipeline loaded.","service.name":"filebeat","pipeline":"filebeat-9.5.1-suricata-eve-dns","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2026-08-15T13:50:14.789+0900","log.logger":"modules","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/fileset.LoadPipeline","file.name":"fileset/pipelines.go","file.line":134},"message":"Elasticsearch pipeline loaded.","service.name":"filebeat","pipeline":"filebeat-9.5.1-suricata-eve-dns-answer-v1","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2026-08-15T13:50:14.840+0900","log.logger":"modules","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/fileset.LoadPipeline","file.name":"fileset/pipelines.go","file.line":134},"message":"Elasticsearch pipeline loaded.","service.name":"filebeat","pipeline":"filebeat-9.5.1-suricata-eve-dns-answer-v2","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2026-08-15T13:50:14.892+0900","log.logger":"modules","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/fileset.LoadPipeline","file.name":"fileset/pipelines.go","file.line":134},"message":"Elasticsearch pipeline loaded.","service.name":"filebeat","pipeline":"filebeat-9.5.1-suricata-eve-tls","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2026-08-15T13:50:14.946+0900","log.logger":"modules","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/fileset.LoadPipeline","file.name":"fileset/pipelines.go","file.line":134},"message":"Elasticsearch pipeline loaded.","service.name":"filebeat","pipeline":"filebeat-9.5.1-suricata-eve-http","ecs.version":"1.6.0"}
-----------------------------------------------------------------------------------------------------------------------------------------
Loaded Ingest pipelines
1.8 Filebeatサービスを開始
# systemctl start filebeat.service
2. Kibanaで確認
作成したユーザーでKibanaにログインし直します。http://192.168.11.85:5601にアクセスします。
一番上の検索フィールドに「Suricata Events Overview」と入力し、Events Overviewをクリック

過去 15 分間のすべての Suricata イベントが表示されます

悪質なトラフィックのアラートを表示するにはSuricataロゴの横にあるAlertsテキストをクリック

Kibana には、ログを視覚化するためのさまざまな機能とツールがありますのでいろいろと試してください。
