Prerequisites
1.Suricata
SURICATA IDS/IPS is an open source IDS that monitors communications on the network and detects suspicious traffic.
The basic mechanism is signature-based, so it can detect predefined unauthorized communications. Suricata is also characterized by its ability to provide protection as well as detection.
2.Elasticsearch,Kibana,Filebeat
Install and configure Elasticsearch so that you can visualize and search SURICATA logs using Kibana and Filebeat
This time, we will install Suricata IDS and ElasticStack on the following server.
・First Server Suricata IDS & Filebeat : OracleLinux9.8 IP address(192.168.11.83)
・Second server Elasticsearch & kibana : OracleLinux10. IP adress(192.168.11.85)
First Server: Suricata Installation
1.Installing and Configuring Suricata
①Suricata Install
# dnf -y install epel-release yum-plugin-copr
# dnf copr enable @oisf/suricata-latest
# dnf -y install suricata
Version Check
# suricata -V
This is Suricata version 7.0.16 RELEASE
②Determine interface and IP address where Suricata will inspect network packets
# ip --brief add
lo UNKNOWN 127.0.0.1/8 ::1/128
ens160 UP 192.168.11.83/24 fe80::20c:29ff:fe12:7ced/64
③Edit configuration file
# vi /etc/suricata/suricata.yaml
Line 18 : Comment out and add below (in the vars section, define the network)
#HOME_NET: "[192.168.0.0/16,10.0.0.0/8,172.16.0.0/12]"
HOME_NET: "[192.168.11.0/24]"
Per Line 142 : Change
community-id: false → community-id: true
Per Line 630 : Set the interface name for the af-packet section
af-packet:
- interface: ens160
# vi /etc/sysconfig/suricata
Line 8 :Specify the interface
#Add options to be passed to the daemon
OPTIONS="-i ens160 --user suricata "
④Suricata rules update
# suricata-update
⑤Activate Suricata
# systemctl enable --now suricata.service
# systemctl start suricata.service
⑥Confirm Suricata startup
# systemctl status suricata.service
● suricata.service - Suricata Intrusion Detection Service
Loaded: loaded (/usr/lib/systemd/system/suricata.service; enabled; preset: disabled)
Active: active (running) since Fri 2026-08-21 08:55:00 JST; 1min 0s ago
Docs: man:suricata(1)
Process: 9708 ExecStartPre=/bin/rm -f /var/run/suricata.pid (code=exited, status=0/SUCCESS)
Main PID: 9716 (Suricata-Main)
Tasks: 8 (limit: 21602)
Memory: 477.4M (peak: 477.4M)
CPU: 31.396s
CGroup: /system.slice/suricata.service
└─9716 /sbin/suricata -c /etc/suricata/suricata.yaml --pidfile /var/run/suricata.pid -i ens160 --user suricata
Aug 21 08:55:00 Lepard systemd[1]: Starting Suricata Intrusion Detection Service...
Aug 21 08:55:00 Lepard systemd[1]: Started Suricata Intrusion Detection Service.
Aug 21 08:55:00 Lepard suricata[9716]: i: suricata: This is Suricata version 7.0.16 RELEASE running in SYSTEM mode
Aug 21 08:55:31 Lepard suricata[9716]: W: af-packet: ens160: AF_PACKET tpacket-v3 is recommended for non-inline operation
Aug 21 08:55:32 Lepard suricata[9716]: i: threads: Threads created -> W: 2 FM: 1 FR: 1 Engine started.
Check Log
# tail /var/log/suricata/suricata.log
[9716 - Suricata-Main] 2026-08-21 08:55:00 Info: logopenfile: fast output device (regular) initialized: fast.log
[9716 - Suricata-Main] 2026-08-21 08:55:00 Info: logopenfile: eve-log output device (regular) initialized: eve.json
[9716 - Suricata-Main] 2026-08-21 08:55:00 Info: logopenfile: stats output device (regular) initialized: stats.log
[9716 - Suricata-Main] 2026-08-21 08:55:17 Info: detect: 1 rule files processed. 52499 rules successfully loaded, 0 rules failed, 0
[9716 - Suricata-Main] 2026-08-21 08:55:17 Info: threshold-config: Threshold config parsed: 0 rule(s) found
[9716 - Suricata-Main] 2026-08-21 08:55:17 Info: detect: 52504 signatures processed. 1322 are IP-only rules, 4511 are inspecting packet payload, 46436 inspect application layer, 109 are decoder event only
[9716 - Suricata-Main] 2026-08-21 08:55:31 Warning: af-packet: ens160: AF_PACKET tpacket-v3 is recommended for non-inline operation
[9716 - Suricata-Main] 2026-08-21 08:55:31 Info: runmodes: ens160: creating 2 threads
[9716 - Suricata-Main] 2026-08-21 08:55:31 Info: unix-manager: unix socket '/var/run/suricata/suricata-command.socket'
[9716 - Suricata-Main] 2026-08-21 08:55:32 Notice: threads: Threads created -> W: 2 FM: 1 FR: 1 Engine started.
Check the stats.log file for statistics (updated every 8 seconds by default)
# tail -f /var/log/suricata/stats.log
A more advanced output, EVE JSON, can be generated with the following command
# tail -f /var/log/suricata/eve.json
2.Suricata Testing
①Run ping test with curl utility
# curl http://testmynids.org/uid/index.html
uid=0(root) gid=0(root) groups=0(root)
②Check the log file using the specified rule number.
Suricata comes with the following two log files enabled by default:
/var/log/suricata/fast.log
/var/log/suricata/eve.log
To check the log entries corresponding to the curl request, use the grep command to examine the /var/log/suricata/fast.log log file.
2100498 Searches for log entries using the rule identifier. (For IPv4)
# grep 2100498 /var/log/suricata/fast.log
08/21/2026-08:58:32.238297 [**] [1:2100498:7] GPL ATTACK_RESPONSE id check returned root [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 13.227.50.46:80 -> 192.168.11.83:51322
③Checking events in /var/log/suricata/eve.log
Install jq
# dnf -y install jq
Search for signature 2100498 to filter EVE log events
Display the alert object with the signature_id key matching the value 2100498
# jq 'select(.alert .signature_id==2100498)' /var/log/suricata/eve.json
{
"timestamp": "2026-08-21T08:58:32.238297+0900",
"flow_id": 108349815455079,
"in_iface": "ens160",
"event_type": "alert",
"src_ip": "13.227.50.46",
"src_port": 80,
"dest_ip": "192.168.11.83",
"dest_port": 51322,
"proto": "TCP",
"pkt_src": "wire/pcap",
"community_id": "1:b/7JzHX6ja/vWabCbthE2HlIsBQ=",
"tx_id": 0,
"tx_guessed": true,
"alert": {
"action": "allowed",
"gid": 1,
"signature_id": 2100498,
"rev": 7,
"signature": "GPL ATTACK_RESPONSE id check returned root",
"category": "Potentially Bad Traffic",
"severity": 2,
"metadata": {
"confidence": [
"Medium"
],
"created_at": [
"2010_09_23"
],
"signature_severity": [
"Informational"
],
"updated_at": [
"2019_07_26"
]
}
},
"http": {
"hostname": "testmynids.org",
"url": "/uid/index.html",
"http_user_agent": "curl/7.76.1",
"http_content_type": "text/html",
"http_method": "GET",
"protocol": "HTTP/1.1",
"status": 200,
"length": 39
},
"files": [
{
"filename": "/uid/index.html",
"gaps": false,
"state": "CLOSED",
"stored": false,
"size": 39,
"tx_id": 0
}
],
"app_proto": "http",
"direction": "to_client",
"flow": {
"pkts_toserver": 5,
"pkts_toclient": 4,
"bytes_toserver": 430,
"bytes_toclient": 810,
"start": "2026-08-21T08:58:32.221835+0900",
"src_ip": "192.168.11.83",
"dest_ip": "13.227.50.46",
"src_port": 51322,
"dest_port": 80
}
}
3.Setting Suricata Rules
①Display of rule sets packaged in Suricata
# ls -al /var/lib/suricata/rules/
total 44236
drwxr-s--- 2 root suricata 57 Aug 21 08:54 .
drwxrws--- 4 suricata suricata 33 Aug 21 08:54 ..
-rw-r--r-- 1 root suricata 3228 Aug 21 08:54 classification.config
-rw-r--r-- 1 root suricata 45290853 Aug 21 08:54 suricata.rules
②Index list of sources providing rule sets
# suricata-update list-sources
Name: abuse.ch/feodotracker
Vendor: Abuse.ch
Summary: Abuse.ch Feodo Tracker Botnet C2 IP ruleset
License: CC0-1.0
Name: abuse.ch/sslbl-blacklist
Vendor: Abuse.ch
Summary: Abuse.ch SSL Blacklist
License: CC0-1.0
Replaces: sslbl/ssl-fp-blacklist
Name: abuse.ch/sslbl-c2
Vendor: Abuse.ch
Summary: Abuse.ch Suricata Botnet C2 IP Ruleset
License: CC0-1.0
Name: abuse.ch/sslbl-ja3
Vendor: Abuse.ch
Summary: Abuse.ch Suricata JA3 Fingerprint Ruleset
License: CC0-1.0
Replaces: sslbl/ja3-fingerprints
Name: abuse.ch/urlhaus
Vendor: abuse.ch
Summary: Abuse.ch URLhaus Suricata Rules
License: CC0-1.0
Name: aleksibovellan/nmap
Vendor: aleksibovellan
Summary: Suricata IDS/IPS Detection Rules Against NMAP Scans
License: MIT
Name: et/open
Vendor: Proofpoint
Summary: Emerging Threats Open Ruleset
License: MIT
Name: et/pro
Vendor: Proofpoint
Summary: Emerging Threats Pro Ruleset
License: Commercial
Replaces: et/open
Parameters: secret-code
Subscription: https://www.proofpoint.com/us/threat-insight/et-pro-ruleset
Name: etnetera/aggressive
Vendor: Etnetera a.s.
Summary: Etnetera aggressive IP blacklist
License: MIT
Name: oisf/trafficid
Vendor: OISF
Summary: Suricata Traffic ID ruleset
License: MIT
Name: pawpatrules
Vendor: pawpatrules
Summary: PAW Patrules is a collection of rules for IDPS / NSM Suricata engine
License: CC-BY-SA-4.0
Name: ptrules/open
Vendor: Positive Technologies
Summary: Positive Technologies Open Ruleset
License: Custom
Name: scwx/enhanced
Vendor: Secureworks
Summary: Secureworks suricata-enhanced ruleset
License: Commercial
Parameters: secret-code
Subscription: https://www.secureworks.com/contact/ (Please reference CTU Countermeasures)
Name: scwx/malware
Vendor: Secureworks
Summary: Secureworks suricata-malware ruleset
License: Commercial
Parameters: secret-code
Subscription: https://www.secureworks.com/contact/ (Please reference CTU Countermeasures)
Name: scwx/security
Vendor: Secureworks
Summary: Secureworks suricata-security ruleset
License: Commercial
Parameters: secret-code
Subscription: https://www.secureworks.com/contact/ (Please reference CTU Countermeasures)
Name: stamus/lateral
Vendor: Stamus Networks
Summary: Lateral movement rules
License: GPL-3.0-only
Name: stamus/nrd-14-open
Vendor: Stamus Networks
Summary: Newly Registered Domains Open only - 14 day list, complete
License: Commercial
Parameters: secret-code
Subscription: https://www.stamus-networks.com/stamus-labs/subscribe-to-threat-intel-feed
Name: stamus/nrd-30-open
Vendor: Stamus Networks
Summary: Newly Registered Domains Open only - 30 day list, complete
License: Commercial
Parameters: secret-code
Subscription: https://www.stamus-networks.com/stamus-labs/subscribe-to-threat-intel-feed
Name: stamus/nrd-entropy-14-open
Vendor: Stamus Networks
Summary: Newly Registered Domains Open only - 14 day list, high entropy
License: Commercial
Parameters: secret-code
Subscription: https://www.stamus-networks.com/stamus-labs/subscribe-to-threat-intel-feed
Name: stamus/nrd-entropy-30-open
Vendor: Stamus Networks
Summary: Newly Registered Domains Open only - 30 day list, high entropy
License: Commercial
Parameters: secret-code
Subscription: https://www.stamus-networks.com/stamus-labs/subscribe-to-threat-intel-feed
Name: stamus/nrd-phishing-14-open
Vendor: Stamus Networks
Summary: Newly Registered Domains Open only - 14 day list, phishing
License: Commercial
Parameters: secret-code
Subscription: https://www.stamus-networks.com/stamus-labs/subscribe-to-threat-intel-feed
Name: stamus/nrd-phishing-30-open
Vendor: Stamus Networks
Summary: Newly Registered Domains Open only - 30 day list, phishing
License: Commercial
Parameters: secret-code
Subscription: https://www.stamus-networks.com/stamus-labs/subscribe-to-threat-intel-feed
Name: tgreen/hunting
Vendor: tgreen
Summary: Threat hunting rules
License: GPLv3
③Enable source (if tgreen/hunting is enabled)
# suricata-update enable-source tgreen/hunting
21/8/2026 -- 09:14:57 - <Info> -- Using data-directory /var/lib/suricata.
21/8/2026 -- 09:14:57 - <Info> -- Using Suricata configuration /etc/suricata/suricata.yaml
21/8/2026 -- 09:14:57 - <Info> -- Using /usr/share/suricata/rules for Suricata provided rules.
21/8/2026 -- 09:14:57 - <Info> -- Found Suricata version 7.0.16 at /usr/sbin/suricata.
21/8/2026 -- 09:14:57 - <Warning> -- Source index does not exist, will use bundled one.
21/8/2026 -- 09:14:57 - <Warning> -- Please run suricata-update update-sources.
21/8/2026 -- 09:14:57 - <Info> -- Creating directory /var/lib/suricata/update/sources
21/8/2026 -- 09:14:57 - <Info> -- Enabling default source et/open
21/8/2026 -- 09:14:57 - <Info> -- Source tgreen/hunting enabled
Perform update
# suricata-update update-sources
Restart Suricata service
# systemctl restart suricata.service
4. Configuring Suricata as an IPS
Configure Suricata to run in IPS mode to drop malicious network traffic.
Create the following custom signature to scan SSH traffic to non-SSH ports, and include it in the file /var/lib/suricata/rules/local.rules.
(Assuming the SSH port is 22)
# vi /var/lib/suricata/rules/local.rules
alert ssh any any -> 192.168.11.83 !22 (msg:"SSH TRAFFIC on non-SSH port"; flow:to_client, not_established; classtype: misc-attack; target: dest_ip; sid:1000000;)
Edit the /etc/suricata/suricata.yaml configuration file and include local.rules.
# vi /etc/suricata/suricata.yaml
Added on line 2238
rule-files:
- suricata.rules
- local.rules
Verify SURICATA Configuration
# suricata -T -c /etc/suricata/suricata.yaml -v
Notice: suricata: This is Suricata version 7.0.16 RELEASE running in SYSTEM mode
Info: cpu: CPUs/cores online: 2
Info: suricata: Running suricata under test mode
Info: suricata: Setting engine mode to IDS mode by default
Info: exception-policy: master exception-policy set to: auto
Info: logopenfile: fast output device (regular) initialized: fast.log
Info: logopenfile: eve-log output device (regular) initialized: eve.json
Info: logopenfile: stats output device (regular) initialized: stats.log
Info: detect: 2 rule files processed. 52500 rules successfully loaded, 0 rules failed, 0
Info: threshold-config: Threshold config parsed: 0 rule(s) found
Info: detect: 52505 signatures processed. 1322 are IP-only rules, 4511 are inspecting packet payload, 46437 inspect application layer, 109 are decoder event only
Notice: suricata: Configuration provided was successfully loaded. Exiting.
Edit the SURICATA configuration file located at /etc/sysconfig/suricata
# vi /etc/sysconfig/suricata
Line 8 : Comment out and add the following:
# OPTIONS="-i ens160 --user suricata"
OPTIONS="-q 0 -vvv --user suricata"
Restart Suricata
# systemctl restart suricata.service
Direct incoming network traffic to Suricata's NFQUEUE
Firewalld is installed and enabled, so add the necessary rules for Suricata to Firewalld.(Assuming the SSH port is 22)
# firewall-cmd --permanent --direct --add-rule ipv4 filter INPUT 0 -p tcp --dport 22 -j NFQUEUE --queue-bypass
# firewall-cmd --permanent --direct --add-rule ipv4 filter OUTPUT 0 -p tcp --sport 22 -j NFQUEUE --queue-bypass
# firewall-cmd --permanent --direct --add-rule ipv6 filter INPUT 0 -p tcp --dport 22 -j NFQUEUE --queue-bypass
# firewall-cmd --permanent --direct --add-rule ipv6 filter OUTPUT 0 -p tcp --sport 22 -j NFQUEUE --queue-bypas
# firewall-cmd --permanent --direct --add-rule ipv4 filter FORWARD 0 -j NFQUEUE
# firewall-cmd --permanent --direct --add-rule ipv6 filter FORWARD 0 -j NFQUEUE
# firewall-cmd --permanent --direct --add-rule ipv4 filter INPUT 1 -j NFQUEUE
# firewall-cmd --permanent --direct --add-rule ipv4 filter OUTPUT 1 -j NFQUEUE
# firewall-cmd --permanent --direct --add-rule ipv6 filter INPUT 1 -j NFQUEUE
# firewall-cmd --permanent --direct --add-rule ipv6 filter OUTPUT 1 -j NFQUEUE
# firewall-cmd --reload
Verify that SURICATA is correctly dropping traffic.
Switch the signature's default action from alert or log to active dropping traffic.
Open the /var/lib/suricata/rules/suricata.rules file and comment out any entries matching sid:2100498.
# vi /var/lib/suricata/rules/suricata.rules
#alert ip any any -> any any (msg:"GPL ATTACK_RESPONSE id check returned root"; content:"uid=0|28|root|29|"; classtype:bad-unknown; sid:2100498; rev:7; metadata:created_at 2010_09_23, confidence Medium, signature_severity Informational, updated_at 2019_07_26;)
Create a new rule named sid:2100498 in /var/lib/suricata/rules/local.rules.
# vi /var/lib/suricata/rules/local.rules
drop ip any any -> any any (msg:"GPL ATTACK_RESPONSE id check returned root"; content:"uid=0|28|root|29|"; classtype:bad-unknown; sid:2100498; rev:7; metadata:created_at 2010_09_23, confidence Medium, signature_severity Informational, updated_at 2019_07_26;)
Suricata restart
# systemctl restart suricata.service
Test this rule using curl
# curl --max-time 5 http://testmynids.org/uid/index.html
curl: (28) Operation timed out after 5000 milliseconds with 0 out of 39 bytes received
Use jq to examine the eve.log file
# jq 'select(.alert .signature_id==2100498)' /var/log/suricata/eve.json
{
"timestamp": "2026-08-21T09:30:24.912199+0900",
"flow_id": 207729072678478,
"event_type": "alert",
"src_ip": "13.227.50.49",
"src_port": 80,
"dest_ip": "192.168.11.83",
"dest_port": 53118,
"proto": "TCP",
"pkt_src": "wire/pcap",
"community_id": "1:igDvy7xDQxZfHYIpAP4NBNxaUnM=",
"tx_id": 0,
"tx_guessed": true,
"alert": {
"action": "blocked",
"gid": 1,
"signature_id": 2100498,
"rev": 7,
"signature": "GPL ATTACK_RESPONSE id check returned root",
"category": "Potentially Bad Traffic",
"severity": 2,
"metadata": {
"confidence": [
"Medium"
],
"created_at": [
"2010_09_23"
],
"signature_severity": [
"Informational"
],
"updated_at": [
"2019_07_26"
]
}
},
"http": {
"hostname": "testmynids.org",
"url": "/uid/index.html",
"http_user_agent": "curl/7.76.1",
"http_content_type": "text/html",
"http_method": "GET",
"protocol": "HTTP/1.1",
"status": 200,
"length": 39
},
"files": [
{
"filename": "/uid/index.html",
"gaps": false,
"state": "CLOSED",
"stored": false,
"size": 39,
"tx_id": 0
}
],
"app_proto": "http",
"direction": "to_client",
"flow": {
"pkts_toserver": 3,
"pkts_toclient": 4,
"bytes_toserver": 256,
"bytes_toclient": 754,
"start": "2026-08-21T09:30:24.900333+0900",
"src_ip": "192.168.11.83",
"dest_ip": "13.227.50.49",
"src_port": 53118,
"dest_port": 80
}
}
"action": "blocked", is set
Integration of the ELK Stack and SURICATA
Install and configure the Elastic Stack to visualize and search SURICATA logs more efficiently.
This section is primarily performed on the second OracleLinux 10 server.
1. Elasticsearch Install
1.1 Download and install the GPG key
# rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch
1.2 Create the repository definition in the /etc/yum/yum.repos.d directory.
# vi /etc/yum.repos.d/elasticsearch.repo
Describe the following content
[elasticsearch]
name=Elasticsearch repository for 9.x packages
baseurl=https://artifacts.elastic.co/packages/9.x/yum
gpgcheck=1
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch
enabled=0
autorefresh=1
type=rpm-md
1.3 Elasticsearch Install
# dnf -y install --enablerepo=elasticsearch elasticsearch
2. Elasticsearch Settings
Elasticsearch is configured by default to accept only local connections.
Additionally, tools such as Filebeat cannot send logs because authentication is not enabled.
This time, we will configure Elasticsearch's network settings and enable the xpack security module built into Elasticsearch.
2.1 Elasticsearch Network Configuration
Since the Elasticsearch and SURICATA servers are separate, Elasticsearch must be configured to listen for connections on the private network interface.
# vi /etc/elasticsearch/elasticsearch.yml
Line 57 : Add local address to Elasticsearch server
#network.host: 192.168.0.1
network.host: 192.168.11.85
Line 62 : Uncomments
http.port: 9200
2.2 Start Elasticsearch
# systemctl daemon-reload
# systemctl enable elasticsearch.service
# systemctl start elasticsearch.service
2.3 Create passwords for elastic and kibana_system
Be sure to copy the passwords for the elastic user and kibana_system user, as they will be needed later.
The kibana_system user is used for configuring Kibana.
The elastic user is used for configuring Filebeat and Auditbeat, and for logging into Kibana.
If you forget your password, you can use the command again to reset it.
[elastic] User password creation
# cd /usr/share/elasticsearch/bin
# ./elasticsearch-reset-password -u elastic
This tool will reset the password of the [elastic] user to an autogenerated value.
The password will be printed in the console.
Please confirm that you would like to continue [y/N]y
Password for the [elastic] user successfully reset.
New value: OeWPX7i7O9-0CAMlYqXj
※Resetting Elasticsearch Passwords
The automatically generated Elastic user password is too complex, so you can reset it using the /usr/share/elasticsearch/bin/elasticsearch-reset-password command.
To reset your password, execute the command.
# /usr/share/elasticsearch/bin/elasticsearch-reset-password -u elastic -i
This tool will reset the password of the [elastic] user.
You will be prompted to enter the password.
Please confirm that you would like to continue [y/N]y
Enter password for [elastic]:
Re-enter password for [elastic]:
Password for the [elastic] user successfully reset.
[kibana_system] User Password Creation
# cd /usr/share/elasticsearch/bin
# ./elasticsearch-reset-password -u kibana_system
This tool will reset the password of the [kibana_system] user to an autogenerated value.
The password will be printed in the console.
Please confirm that you would like to continue [y/N]y
Password for the [kibana_system] user successfully reset.
New value: wUivgRyCcG_CJzRdjrfV
3. Installing and Configuring Kibana
This section will be performed on the second Oracle Linux 10 server.
3.1 Kibana Installation
# dnf -y install --enablerepo=elasticsearch kibana
Installed:
kibana-9.5.2-1.x86_64
Complete!
3.2 xpack Security Module Configuration
Enable Kibana's xpack security features to generate several encryption keys that Kibana uses to store data in Elasticsearch.
Encryption keys are created using the kibana-encryption-keys utility located in the /usr/share/kibana/bin directory.
Store the three keys you created in a secure location.
# cd /usr/share/kibana/bin/
# ./kibana-encryption-keys generate -q --force
xpack.encryptedSavedObjects.encryptionKey: d2615b85d07e89c0af5be03814f09c35c4bd3ba4d4d1122e75c7d98bced45ce7
xpack.reporting.encryptionKey: 55c6871705e2361e5beb475cdd2ff8addc281b4fac147f5e6007ef3dde2720f8
xpack.security.encryptionKey: 7c46038a551b4899b77f6c558a03a7fe3981ebec72a1f576f4ad8b109b2a1845
Add these keys to Kibana's /etc/kibana/kibana.yml configuration file.
# vi /etc/kibana/kibana.yml
Described in the last line
xpack.encryptedSavedObjects.encryptionKey: d2615b85d07e89c0af5be03814f09c35c4bd3ba4d4d1122e75c7d98bced45ce7
xpack.reporting.encryptionKey: 55c6871705e2361e5beb475cdd2ff8addc281b4fac147f5e6007ef3dde2720f8
xpack.security.encryptionKey: 7c46038a551b4899b77f6c558a03a7fe3981ebec72a1f576f4ad8b109b2a1845
3.3 Kibana Network Configuration
# vi /etc/kibana/kibana.yml
Line 6 : Uncomments
server.port: 5601
Line 12 : Add the server's private IP address (192.168.11.85)
# server.host: "localhost"
server.host: "192.168.11.85"
3.4 Generating a Kibana-Elasticsearch Enrollment Token
To configure a Kibana instance to communicate with an existing Elasticsearch cluster with security enabled, an enrollment token is required. An enrollment token for Kibana can be generated using the following command:
# /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s kibana
eyJ2ZXIiOiI4LjE0LjAiLCJhZHIiOlsiMTkyLjE2OC4xMS44NTo5MjAwIl0sImZnciI6IjI4ODM5MzViYmJkMDIxZTkxZmZhYzRlZjUwZjQzNDdhNTc3MzA0ODU0ZDg5OTAwNjRlY2IzNGEwOWEzYjliYzkiLCJrZXkiOiI5V2pWSWFBQkpIeTJyQi1aeV9vRTpZVjJ3NEZCY2lOX0sweXNaMDE0bmNnIn0=
3.5 Starting Kibana
Launch Kibana 9 and configure it to run at system startup.
# systemctl enable --now kibana.service
# systemctl start kibana.service
Status Check
# systemctl status kibana.service
● kibana.service - Kibana
Loaded: loaded (/usr/lib/systemd/system/kibana.service; enabled; preset: disabled)
Active: active (running) since Fri 2026-08-21 10:01:45 JST; 45s ago
Invocation: f5d17c08658c412085e8b88e1d464af1
Docs: https://www.elastic.co
Main PID: 8350 (MainThread)
Tasks: 11 (limit: 15512)
Memory: 871.7M (peak: 879.3M)
CPU: 15.702s
CGroup: /system.slice/kibana.service
mq8350 /usr/share/kibana/bin/../node/default/bin/node /usr/share/kibana/bin/../node_modules/@kbn/cli/kibana/dist
Aug 21 10:01:49 Lion kibana[8350]: Native global console methods have been overridden in production environment.
Aug 21 10:01:52 Lion kibana[8350]: [2026-08-21T10:01:52.529+09:00][INFO ][root] Kibana is starting
Aug 21 10:01:52 Lion kibana[8350]: [2026-08-21T10:01:52.649+09:00][INFO ][node] Kibana process configured with roles: [backgr>
Aug 21 10:02:03 Lion kibana[8350]: [2026-08-21T10:02:03.770+09:00][INFO ][plugins-service] The following plugins are disabled>
Aug 21 10:02:03 Lion kibana[8350]: [2026-08-21T10:02:03.851+09:00][INFO ][http.server.Preboot] http server running at http://>
Aug 21 10:02:04 Lion kibana[8350]: [2026-08-21T10:02:04.872+09:00][INFO ][plugins-system.preboot] Setting up [1] plugins: [in>
Aug 21 10:02:05 Lion kibana[8350]: [2026-08-21T10:02:05.325+09:00][INFO ][preboot] "interactiveSetup" plugin is holding setup>
Aug 21 10:02:05 Lion kibana[8350]: [2026-08-21T10:02:05.357+09:00][INFO ][root] Holding setup until preboot stage is complete>
Aug 21 10:02:14 Lion kibana[8350]: i Kibana has not been configured.
Aug 21 10:02:14 Lion kibana[8350]: Go to http://192.168.11.85:5601/?code=548774 to get started.
The following appears toward the end of the output:
Go to http://192.168.11.85:5601/?code=548774 to get started.
Copy the provided Kibana URL (including the code) and use it in your browser to access Kibana and complete the setup.
4. Accessing the Kibana 9 Dashboard
If the firewall is running, open the Kibana port.
# firewall-cmd --add-port=5601/tcp --permanent
# firewall-cmd --reload
Accsess http://192.168.11.85:5601/?code=548774
When you access Kibana 9, the welcome page prompts you to configure Elastic.
First, enter the generated registration token.
Copy the Kibana token generated using the command /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s kibana and paste it into the box.Copy the Kibana token generated using the command `/usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s kibana` and paste it into the box.

Paste the token, and Kibana will automatically connect to Elasticsearch.
Click Configure Elastic. Your settings will be saved, and Elasticsearch will be configured and restarted.

Proceed to the login page. Log in using the generated Elastic user credentials.
Username : elastic
Password : Password regenerated for clarity

On the welcome page, click "Explore on my own" to proceed to the Kibana 9.x dashboard.


Create a new user account so that you do not need to use the elastic superuser account.
Open the main menu, then navigate to Management > Stack Management > Security > Users

Click the "Create user" button in the upper right corner.

Enter new user information and assign the kibana_admin, kibana_system, monitoring_user, and editor roles under Privileges.
Finally, click [Create user].
Log out of the current profile and verify that you can log in with the newly created user account.
Currently, there is no data available to display in Kibana because Filebeat and Auditbeat are not configured on the SURICATA host.
Install Filebeat on the SURICATA server
This task will be performed on the first OracleLinux 9.8 server where Suricata has been installed.
1. Filebeat Install
1.1 Download Elastic GPG Key
# rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch
1.2 Create an elasticsearch.repo file in the /etc/yum/yum.repos.d directory with the following content:
# vi /etc/yum.repos.d/elasticsearch.repo
Please describe the following content.
[elasticsearch]
name=Elasticsearch repository for 9.x packages
baseurl=https://artifacts.elastic.co/packages/9.x/yum
gpgcheck=1
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch
enabled=0
autorefresh=1
type=rpm-md
1.3 Install Filebeat
# dnf -y install --enablerepo=elasticsearch filebeat
Installed:
filebeat-9.5.2-1.x86_64
Complete!
1.4 Creating an Elasticsearch CA Certificate
Download the Elasticsearch CA certificate and save it to any directory (in this case, save it as /etc/filebeat/elastic-ca.crt).
※Keep port 9200 open on the second server (the server running OracleLinux 10 with Elasticsearch installed).
# openssl s_client -connect 192.168.11.85:9200 \
-showcerts </dev/null 2>/dev/null | \
openssl x509 -outform PEM > /etc/filebeat/elastic-ca.crt
1.5 Configure Filebeat to connect to Elasticsearch and Kibana
# vi /etc/filebeat/filebeat.yml
Line 138 : Add a line specifying the private IP address and port of the Kibana instance
host: "192.168.11.85:5601"
Line 164 : comment out
#hosts: ["localhost:9200"]
Line165 : Enter the Elasticsearch IP address and port number
hosts: ["https://192.168.11.85:9200"]
Line 171 : Uncomments
protocol: "https"
Line 172 : Elasticsearch CA Certificate Specification
ssl.certificate_authorities: ["/etc/filebeat/elastic-ca.crt"]
Line 175,176 : Uncomment the line, leave [username] as the default, and enter the password for the [elastic] user in [password].
username: "elastic"
password: “xxxxxxxxx"
1.6 Configuration File Test
# filebeat test config
Config OK
1.7 Enable the built-in Suricata module in Filebeats
# filebeat modules enable suricata
The above command will change /etc/filebeat/modules.d/suricata.yml.disabled to /etc/filebeat/modules.d/suricata.yml, but the contents remain unchanged. Therefore, edit it as follows:
# vi /etc/filebeat/modules.d/suricata.yml
Line 7-8 : Change
eve:
enabled: true
var.paths: ["/var/log/suricata/eve.json"]
1.8 Set up the initial environment
Load the pipeline into the Suricata service
Load the SIEM dashboard into Elasticsearch
# filebeat setup -e
------------------------------------------------------------------------------------------------------------------
{"log.level":"info","@timestamp":"2026-08-21T10:34:00.265+0900","log.logger":"modules","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/fileset.LoadPipeline","file.name":"fileset/pipelines.go","file.line":134},"message":"Elasticsearch pipeline loaded.","service.name":"filebeat","pipeline":"filebeat-9.5.2-suricata-eve-pipeline","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2026-08-21T10:34:00.353+0900","log.logger":"modules","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/fileset.LoadPipeline","file.name":"fileset/pipelines.go","file.line":134},"message":"Elasticsearch pipeline loaded.","service.name":"filebeat","pipeline":"filebeat-9.5.2-suricata-eve-dns","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2026-08-21T10:34:00.409+0900","log.logger":"modules","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/fileset.LoadPipeline","file.name":"fileset/pipelines.go","file.line":134},"message":"Elasticsearch pipeline loaded.","service.name":"filebeat","pipeline":"filebeat-9.5.2-suricata-eve-dns-answer-v1","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2026-08-21T10:34:00.456+0900","log.logger":"modules","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/fileset.LoadPipeline","file.name":"fileset/pipelines.go","file.line":134},"message":"Elasticsearch pipeline loaded.","service.name":"filebeat","pipeline":"filebeat-9.5.2-suricata-eve-dns-answer-v2","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2026-08-21T10:34:00.600+0900","log.logger":"modules","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/fileset.LoadPipeline","file.name":"fileset/pipelines.go","file.line":134},"message":"Elasticsearch pipeline loaded.","service.name":"filebeat","pipeline":"filebeat-9.5.2-suricata-eve-tls","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2026-08-21T10:34:00.805+0900","log.logger":"modules","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/fileset.LoadPipeline","file.name":"fileset/pipelines.go","file.line":134},"message":"Elasticsearch pipeline loaded.","service.name":"filebeat","pipeline":"filebeat-9.5.2-suricata-eve-http","ecs.version":"1.6.0"}
------------------------------------------------------------------------------------------------------------------
1.9 Start the Filebeat service
# systemctl start filebeat.service
2. Check in Kibana
Log back into Kibana using the user you created. Accsses http://192.168.11.85:5601
Type "Suricata Events Overview" into the top search field, then click [Filebeat Suricata] Events Overview.

All Suricata events from the past 15 minutes are displayed.

To display alerts for malicious traffic, click the "Alerts" text next to the Suricata logo.

Kibana offers a variety of features and tools for visualizing logs, so feel free to experiment with them.
