業務用エアコン関連の技術情報、エラーコード、環境問題対策に関する別サイト「エアコンの安全な修理・適切なフロン回収」

ArchLinux : Suricata+ELK+Kibana+Beats

Prerequisites

1.Suricata
Suricata IDS/IPS is an open-source intrusion detection system (IDS) that monitors network traffic and detects suspicious activity. Since it operates on a signature-based mechanism, it can detect predefined malicious traffic. Another key feature of Suricata is its ability to not only detect but also prevent such threats.

2.Elasticsearch,Kibana,Filebeat
Install and configure the Elasticsearch to enable visualization and search of SURICATA logs using Kibana and Filebeat

In this session, we will install Suricata IDS and ElasticStack on the following serve
・First server Suricata & Filebeat : ArchLinux IP address(192.168.11.83)
・Second server Elasticsearch & kibana : ArchLinux IP address(192.168.11.85)
This time, we will run it as the root user

  Server 1: Suricata Installation

1.Installing and Configuring Suricata

①Suricata Install

# su - huong
$ yay -S suricata-nfqueue

Version Check
# suricata -V
This is Suricata version 8.0.5 RELEASE

➁Checking and Loading Required Kernel Modules
To use NFQUEUE, the kernel must support nfnetlink_queue.
Module Verification:

# lsmod | grep nfnetlink_queue

If nothing appears above, load the module

# modprobe nfnetlink_queue

Confirm again

# lsmod | grep nfnetlink_queue
nfnetlink_queue        36864  0

Keep this setting active even after a restart

# echo "nfnetlink_queue" | tee /etc/modules-load.d/nfqueue.conf

➂Determine the interfaces and IP addresses that Suricata uses to inspect network packets

# ip --brief add
lo               UNKNOWN        127.0.0.1/8 ::1/128
ens33            UP             192.168.11.83/24 fe80::20c:29ff:fe76:c730/64

④Edit the configuration file

# vim /etc/suricata/suricata.yaml

Line 18 : Comment it out and add the following below it (in the `vars` section, where you define the network)
#HOME_NET: "[192.168.0.0/16,10.0.0.0/8,172.16.0.0/12]"
HOME_NET: "[192.168.11.0/24]"

Per Line158 : Change
community-id: false → community-id: true

Per Line 661 : Set the interface name in the af-packet section
af-packet:
    - interface: ens33

Set directory ownership and execution permissions

# chown -R root:root /tmp
# chmod 775 /tmp

⑤Starting Suricata

# systemctl daemon-reload
# systemctl start suricata
# systemctl enable suricata
Created symlink /etc/systemd/system/multiuser.target.wants/suricata.service → /usr/lib/systemd/system/suricata.service.

⑥Verifying that Suricata is running

# systemctl status suricata

● suricata.service - Suricata IDS/IPS daemon
     Loaded: loaded (/usr/lib/systemd/system/suricata.service; enabled; preset: disabled)
     Active: active (running) since Fri 2026-09-25 09:11:36 JST; 36s ago
 Invocation: da54dc8b4bfd4cbd98cc8dc6982d534f
   Main PID: 30302 (Suricata-Main)
      Tasks: 10 (limit: 4599)
     Memory: 52.8M (peak: 53.1M)
        CPU: 268ms
     CGroup: /system.slice/suricata.service
             mq30302 /usr/bin/suricata -c /etc/suricata/suricata.yaml --pidfile /run/suricata/suricata.pid -q 0

Sep 25 09:11:36 lepard systemd[1]: Started Suricata IDS/IPS daemon.
Sep 25 09:11:36 lepard suricata[30302]: Info: conf-yaml-loader: Including configuration file local.yaml.
Sep 25 09:11:36 lepard suricata[30302]: i: suricata: This is Suricata version 8.0.5 RELEASE running in SYSTEM mode
Sep 25 09:11:36 lepard suricata[30302]: W: detect: No rule files match the pattern /var/lib/suricata/rules/suricata.rules
Sep 25 09:11:36 lepard suricata[30302]: W: detect: 2 rule files specified, but no rules were loaded!
Sep 25 09:11:36 lepard suricata[30302]: i: threads: Threads created -> RX: 1 W: 2 TX: 1 FM: 1 FR: 1   Engine started.

Check the log

# tail /var/log/suricata/suricata.log

To view the statistics, check the stats.log file (updated every 8 seconds by default)

# tail -f /var/log/suricata/stats.log

EVE JSON, which provides more advanced output, can be generated using the following command

# tail -f /var/log/suricata/eve.json

suricata rulesを取得

# suricata-update

2.Configuring Suricata Rules

①Get Suricata rules

# suricata-update

➁Displaying the rule sets included in Suricata

# ls -al /var/lib/suricata/rules/
total 8
drwxr-x--- 2 suricata suricata 4096 Sep 25 09:05 .
drwxr-x--- 5 suricata suricata 4096 Sep 25 09:11 ..
-rw-r----- 1 suricata suricata    0 Sep 25 09:05  suricata.rules

②List of indexes for sources that provide rule sets

# suricata-update list-sources

Name: abuse.ch/feodotracker
  Vendor: Abuse.ch
  Summary: Abuse.ch Feodo Tracker Botnet C2 IP ruleset
  License: CC0-1.0
Name: abuse.ch/sslbl-blacklist
  Vendor: Abuse.ch
  Summary: Abuse.ch SSL Blacklist
  License: CC0-1.0
  Replaces: sslbl/ssl-fp-blacklist
Name: abuse.ch/sslbl-c2
  Vendor: Abuse.ch
  Summary: Abuse.ch Suricata Botnet C2 IP Ruleset
  License: CC0-1.0
Name: abuse.ch/sslbl-ja3
  Vendor: Abuse.ch
  Summary: Abuse.ch Suricata JA3 Fingerprint Ruleset
  License: CC0-1.0
  Replaces: sslbl/ja3-fingerprints
Name: abuse.ch/urlhaus
  Vendor: abuse.ch
  Summary: Abuse.ch URLhaus Suricata Rules
  License: CC0-1.0
Name: aleksibovellan/nmap
  Vendor: aleksibovellan
  Summary: Suricata IDS/IPS Detection Rules Against NMAP Scans
  License: MIT
Name: et/open
  Vendor: Proofpoint
  Summary: Emerging Threats Open Ruleset
  License: MIT
Name: et/pro
  Vendor: Proofpoint
  Summary: Emerging Threats Pro Ruleset
  License: Commercial
  Replaces: et/open
  Parameters: secret-code
  Subscription: https://www.proofpoint.com/us/threat-insight/et-pro-ruleset
Name: etnetera/aggressive
  Vendor: Etnetera a.s.
  Summary: Etnetera aggressive IP blacklist
  License: MIT
Name: oisf/trafficid
  Vendor: OISF
  Summary: Suricata Traffic ID ruleset
  License: MIT
Name: pawpatrules
  Vendor: pawpatrules
  Summary: PAW Patrules is a collection of rules for IDPS / NSM Suricata engine
  License: CC-BY-SA-4.0
Name: ptrules/open
  Vendor: Positive Technologies
  Summary: Positive Technologies Open Ruleset
  License: Custom
Name: scwx/enhanced
  Vendor: Secureworks
  Summary: Secureworks suricata-enhanced ruleset
  License: Commercial
  Parameters: secret-code
  Subscription: https://www.secureworks.com/contact/ (Please reference CTU Countermeasures)
Name: scwx/malware
  Vendor: Secureworks
  Summary: Secureworks suricata-malware ruleset
  License: Commercial
  Parameters: secret-code
  Subscription: https://www.secureworks.com/contact/ (Please reference CTU Countermeasures)
Name: scwx/security
  Vendor: Secureworks
  Summary: Secureworks suricata-security ruleset
  License: Commercial
  Parameters: secret-code
  Subscription: https://www.secureworks.com/contact/ (Please reference CTU Countermeasures)
Name: stamus/lateral
  Vendor: Stamus Networks
  Summary: Lateral movement rules
  License: GPL-3.0-only
Name: stamus/nrd-14-open
  Vendor: Stamus Networks
  Summary: Newly Registered Domains Open only - 14 day list, complete
  License: Commercial
  Parameters: secret-code
  Subscription: https://www.stamus-networks.com/stamus-labs/subscribe-to-threat-intel-feed
Name: stamus/nrd-30-open
  Vendor: Stamus Networks
  Summary: Newly Registered Domains Open only - 30 day list, complete
  License: Commercial
  Parameters: secret-code
  Subscription: https://www.stamus-networks.com/stamus-labs/subscribe-to-threat-intel-feed
Name: stamus/nrd-entropy-14-open
  Vendor: Stamus Networks
  Summary: Newly Registered Domains Open only - 14 day list, high entropy
  License: Commercial
  Parameters: secret-code
  Subscription: https://www.stamus-networks.com/stamus-labs/subscribe-to-threat-intel-feed
Name: stamus/nrd-entropy-30-open
  Vendor: Stamus Networks
  Summary: Newly Registered Domains Open only - 30 day list, high entropy
  License: Commercial
  Parameters: secret-code
  Subscription: https://www.stamus-networks.com/stamus-labs/subscribe-to-threat-intel-feed
Name: stamus/nrd-phishing-14-open
  Vendor: Stamus Networks
  Summary: Newly Registered Domains Open only - 14 day list, phishing
  License: Commercial
  Parameters: secret-code
  Subscription: https://www.stamus-networks.com/stamus-labs/subscribe-to-threat-intel-feed
Name: stamus/nrd-phishing-30-open
  Vendor: Stamus Networks
  Summary: Newly Registered Domains Open only - 30 day list, phishing
  License: Commercial
  Parameters: secret-code
  Subscription: https://www.stamus-networks.com/stamus-labs/subscribe-to-threat-intel-feed
Name: tgreen/hunting
  Vendor: tgreen
  Summary: Threat hunting rules
  License: GPLv3

③Enable the source (if enabling tgreen/hunting)

# suricata-update enable-source tgreen/hunting

25/9/2026 -- 09:19:18 - <Info> -- Using data-directory /var/lib/suricata.
25/9/2026 -- 09:19:18 - <Info> -- Using Suricata configuration /etc/suricata/suricata.yaml
25/9/2026 -- 09:19:18 - <Info> -- Using /usr/share/suricata/rules for Suricata provided rules.
25/9/2026 -- 09:19:18 - <Info> -- Found Suricata version 8.0.5 at /usr/bin/suricata.
25/9/2026 -- 09:19:18 - <Warning> -- Source index does not exist, will use bundled one.
25/9/2026 -- 09:19:18 - <Warning> -- Please run suricata-update update-sources.
25/9/2026 -- 09:19:18 - <Info> -- Creating directory /var/lib/suricata/update/sources
25/9/2026 -- 09:19:18 - <Info> -- Enabling default source et/open
25/9/2026 -- 09:19:18 - <Info> -- Source tgreen/hunting enabled

Run the update

# suricata-update  update-sources

Suricata service restart

# systemctl restart suricata

3. Configuring Suricata as an IPS

①Return to nfqueue mode

# vim /usr/lib/systemd/system/suricata.service

Line 12 : Uncomment
ExecStart=/usr/bin/suricata -c /etc/suricata/suricata.yaml --pidfile /run/suricata/suricata.pid -q 0

Line 13 : Comments
#ExecStart=/usr/bin/suricata -c /etc/suricata/suricata.yaml --pidfile /run/suricata/suricata.pid -i ens33 --user suricata

Verifying SURICATA Settings

# suricata -T -c /etc/suricata/suricata.yaml -v
--------------------------------------------------------------------------------------------------
Info: detect: 53245 signatures processed. 1231 are IP-only rules, 4652 are inspecting packet payload, 47126 inspect application layer, 110 are decoder event only
Notice: suricata: Configuration provided was successfully loaded. Exiting.

Suricata service restart

# systemctl daemon-reload
# systemctl restart suricata

Redirect incoming network traffic to Suricata's NFQUEUE
Since Firewalld is installed and enabled, add the rules required by Suricata to Firewalld (assuming the SSH port is 22)

# vim /etc/ufw/before.rules

Per Line 18 : Add
# Don't delete these required lines, otherwise there will be errors
*filter
:ufw-before-input - [0:0]
:ufw-before-output - [0:0]
:ufw-before-forward - [0:0]
:ufw-not-local - [0:0]
# End required lines
 
## Start Suricata NFQUEUE rules
-I INPUT 1 -p tcp --dport 22 -j NFQUEUE --queue-bypass
-I OUTPUT 1 -p tcp --sport 22 -j NFQUEUE --queue-bypass
-I FORWARD -j NFQUEUE
-I INPUT 2 -j NFQUEUE
-I OUTPUT 2 -j NFQUEUE
## End Suricata NFQUEUE rules

Similarly, edit /etc/ufw/before6.rules

# vim /etc/ufw/before6.rules

Apply Firewall Rules

# ufw reload

Verify that SURICATA is dropping traffic correctly
Change the default action for signatures from "alert" or "log" to "active dropping traffic"
Open the /var/lib/suricata/rules/suricata.rules file and comment out any entries matching "sid:2100498"

# vim /var/lib/suricata/rules/suricata.rules
#alert ip any any -> any any (msg:"GPL ATTACK_RESPONSE id check returned root"; content:"uid=0|28|root|29|"; classtype:bad-unknown; sid:2100498; rev:7; metadata:created_at 2010_09_23, confidence Medium, signature_severity Informational, updated_at 2019_07_26;)


Create the file /var/lib/suricata/rules/local.rules and write the rule with the SID 2100498.

# vim /var/lib/suricata/rules/local.rules

drop ip any any -> any any (msg:"GPL ATTACK_RESPONSE id check returned root"; content:"uid=0|28|root|29|"; classtype:bad-unknown; sid:2100498; rev:7; metadata:created_at 2010_09_23, confidence Medium, signature_severity Informational, updated_at 2019_07_26;)

Edit the SURICATA configuration file to define the path for custom rules

# vim /etc/suricata/suricata.yaml

Line 2327 : Add
rule-files:
  - suricata.rules
  - local.rules

Suricata service restart

# systemctl restart suricata

Test this rule using curl

# curl --max-time 5 http://testmynids.org/uid/index.html
curl: (6) Could not resolve host: testmynids.org

At this stage of the process, the message "Host not found" appears as shown above, so I downloaded the script from GitHub and ran it as described below.

# curl -sSL https://raw.githubusercontent.com/3CORESec/testmynids.org/master/tmNIDS -o /tmp/tmNIDS && chmod +x /tmp/tmNIDS && /tmp/tmNIDS

Examining the eve.log file using jq
Install jq

# pacman -S jq
# jq 'select(.alert .signature_id==2100498)' /var/log/suricata/eve.json
{
  "timestamp": "2026-09-25T10:08:54.302742+0900",
  "flow_id": 1409022830884306,
  "event_type": "alert",
  "src_ip": "217.160.0.187",
  "src_port": 80,
  "dest_ip": "192.168.11.83",
  "dest_port": 46282,
  "proto": "TCP",
  "ip_v": 4,
  "pkt_src": "wire/pcap",
  "community_id": "1:fDwcunrjTZ1tMh4aUPKQxx0W3bs=",
  "alert": {
    "action": "blocked",
    "gid": 1,
    "signature_id": 2100498,
    "rev": 7,
    "signature": "GPL ATTACK_RESPONSE id check returned root",
    "category": "Potentially Bad Traffic",
    "severity": 2,
    "metadata": {
      "confidence": [
        "Medium"
      ],
      "created_at": [
        "2010_09_23"
      ],
      "signature_severity": [
        "Informational"
      ],
      "updated_at": [
        "2019_07_26"
      ]
    }
  },

"action" is set to "blocked"

Elasticsearch

Install and configure the Elastic Stack to visualize and search SURICATA logs more efficiently
This section will primarily be performed on the second ArchLinux server (IP 192.168.11.85).

1. Installing Elasticsearch

In this guide, we will download the archive for Elasticsearch 8.x from the official website and install it. Since Elasticsearch 8.x includes a Java Runtime Environment (JVM), you do not need to install Java on your system beforehand.

1.1 Download the Archive

# wget https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-8.19.22-linux-x86_64.tar.gz

1.2 Extracting and Placing the Archive
Place it in the /opt directory

# tar -xzf elasticsearch-8.19.22-linux-x86_64.tar.gz
# mv elasticsearch-8.19.22 /opt/elasticsearch

2. Creating Dedicated Users and Setting Permissions

For security reasons, Elasticsearch does not allow startup as the root user. Create a dedicated user and group, and change the directory ownership.

Creating Dedicated Groups and Users
# groupadd elasticsearch
# useradd -r -g elasticsearch -d /opt/elasticsearch -s /sbin/nologin elasticsearch

Change of Ownership
# chown -R elasticsearch:elasticsearch /opt/elasticsearch

3. Initial Setup and First Launch

Security features are automatically enabled in Elasticsearch 8 when it is started for the first time. At this point, the initial password and token for the elastic user will be displayed on the console screen, so be sure to make a note of them.

Switch to the dedicated user you created and run the startup script.

# sudo -u elasticsearch /opt/elasticsearch/bin/elasticsearch

The following information will appear on the console screen, so be sure to write it down.
・Password for the elastic user: (Administrator's Initial Password)
・HTTP CA certificate SHA-256 fingerprint: (Certificate Fingerprint)
・Configure Kibana to use this cluster: (Token for Kibana Integration)

Elasticsearch security features have been automatically configured!
Authentication is enabled and cluster connections are encrypted.

ℹ️ Password for the elastic user (reset with bin/elasticsearch-reset-password -u elastic):
kYaEN_HCJnTiq*hb1_o-

ℹ️ HTTP CA certificate SHA-256 fingerprint:
9adec632194076852b831ad4d251e806c4bec21ecd81d1b85af4ee25d6122682

ℹ️ Configure Kibana to use this cluster:
~ Run Kibana and click the configuration link in the terminal when Kibana starts.
~ Copy the following enrollment token and paste it into Kibana in your browser (valid for the next 30 minutes):
eyJ2ZXIiOiI4LjE0LjAiLCJhZHIiOlsiMTkyLjE2OC4xMS44NTo5MjAwIl0sImZnciI6IjlhZGVjNjMyMTk0MDc2ODUyYjgzMWFkNGQyNTFlODA2YzRiZWMyMWVjZDgxZDFiODVhZjRlZTI1ZDYxMjI2ODIiLCJrZXkiOiJBZlh0N3FBQjQzb05YYVZLXzdBMjpXOElxMUFsVWlpT1pDQlZNZk5yVWFnIn0=

ℹ️ Configure other nodes to join this cluster:
~ On this node:
⁃ Create an enrollment token with bin/elasticsearch-create-enrollment-token -s node.
⁃ Uncomment the transport.host setting at the end of config/elasticsearch.yml.
⁃ Restart Elasticsearch.
~ On other nodes:
⁃ Start Elasticsearch with bin/elasticsearch --enrollment-token <token>, using the enrollment token that you generated.

4. Elasticsearch configuration

Since the Elasticsearch and SURICATA servers are separate, you need to configure Elasticsearch to listen for connections on a private network interface.

# vim /opt/elasticsearch/config/elasticsearch.yml

Line 17 : Uncomment
cluster.name: my-application

Line 23 : Uncomment
node.name: node-1

Line 57 : Adding a Local Address to the Elasticsearch Server: When Allowing External Access (Set "Allow All" to 0.0.0.0)
#network.host: 192.168.0.1
network.host: 192.168.11.85

Line 62 : Uncomment
http.port: 9200

5. Create a systemd service file

# vim  /etc/systemd/system/elasticsearch.service

Describe the following
[Unit]
Description=Elasticsearch
Documentation=https://elastic.co
Wants=network-online.target
After=network-online.target

[Service]
Type=simple
RuntimeDirectory=elasticsearch
PrivateTmp=true
Environment=ES_HOME=/opt/elasticsearch
Environment=ES_PATH_CONF=/opt/elasticsearch/config
ExecStart=/opt/elasticsearch/bin/elasticsearch
User=elasticsearch
Group=elasticsearch
LimitNOFILE=65535
LimitNPROC=4096
LimitMEMLOCK=infinity
LimitFSIZE=infinity
TimeoutStopSec=20

[Install]
WantedBy=multi-user.target
# systemctl daemon-reload
# systemctl enable elasticsearch.service
# systemctl start elasticsearch.service

6. Functionality Verification

Enter your password, and if you receive JSON similar to the following, the installation was successful.

# curl --cacert /opt/elasticsearch/config/certs/http_ca.crt -u elastic https://192.168.11.85:9200

Enter host password for user 'elastic':
{
  "name" : "node-1",
  "cluster_name" : "my-application",
  "cluster_uuid" : "HDvKpWVFSyqCCUbiWME0NQ",
  "version" : {
    "number" : "8.19.22",
    "build_flavor" : "default",
    "build_type" : "tar",
    "build_hash" : "3b2a41103de35e0af4064d647974032fcc1bcde9",
    "build_date" : "2026-09-18T10:10:07.018982263Z",
    "build_snapshot" : false,
    "lucene_version" : "9.12.2",
    "minimum_wire_compatibility_version" : "7.17.0",
    "minimum_index_compatibility_version" : "7.0.0"
  },
  "tagline" : "You Know, for Search"
}

※Reference: Resetting Your Elasticsearch Password
Since the automatically generated Elastic user password is too complex, you can reset it using the /usr/share/elasticsearch/bin/elasticsearch-reset-password command.
To reset the password, run the command

# /opt/elasticsearch/bin/elasticsearch-reset-password -u elastic -i

This tool will reset the password of the [elastic] user.
You will be prompted to enter the password.
Please confirm that you would like to continue [y/N]y


Enter password for [elastic]:
Re-enter password for [elastic]: 
Password for the [elastic] user successfully reset.

3. Kibana

This section will be performed on a second ArchLinux server.

Verification of Prerequisites

  • Elasticsearch 8 (the same version) must be installed and running beforehand.
  • If you want to allow access from an external source (such as a browser), you must open TCP port 5601 on the server beforehand.

3.1 Installing Kibana

Download the archive and extract it to the /opt directory

# cd /opt
# wget https://artifacts.elastic.co/downloads/kibana/kibana-8.19.22-linux-x86_64.tar.gz
# tar -xzf kibana-8.19.22-linux-x86_64.tar.gz
# mv kibana-8.19.22 kibana
# rm kibana-8.19.22-linux-x86_64.tar.gz

3.2 Creating an Executive User and Setting Permissions

# useradd -r -s /bin/false kibana
# chown -R kibana:kibana /opt/kibana

3.3 Initial Setup and Integration with Elasticsearch

Starting with Kibana 8, the easiest way to configure encrypted communication (TLS/SSL) and authentication with Elasticsearch is to use the enrollment token generated when Kibana is first launched.

① Issuing a Token in Elasticsearch
When you installed Elasticsearch, a token for Kibana was issued. However, since it expires after 30 minutes, use the following command to reissue it if it has expired.

# /opt/elasticsearch/bin/elasticsearch-create-enrollment-token -s kibana
eyJ2ZXIiOiI4LjE0LjAiLCJhZHIiOlsiMTkyLjE2OC4xMS44NTo5MjAwIl0sImZnciI6Ijc2NjllYzAwY2RhY2JiZDk4NGZkYWI3ZWFkZDg3YjNiZDQ2OWUzMjM2NGUyOTJmMzhjMDk0ZjI1OTBmMTAyZmQiLCJrZXkiOiIzZUtkNWFBQlBrMFNUX2RFeGd0dDpGenlmSUw4YUc3Q0MyOXdXSEVBbGRBIn0=

➁Editing Kibana Configuration Files

# vim /opt/kibana/config/kibana.yml
 
Line 6 : Uncomment
server.port: 5601

Line 12 : Add
server.host: "192.168.11.85"

3.4 Creating a Kibana Service Using systemd

# vim  /etc/systemd/system/kibana.service

Describe the following
[Unit]
Description=Kibana
After=network.target

[Service]
Type=simple
User=kibana
Group=kibana
WorkingDirectory=/opt/kibana
ExecStart=/opt/kibana/bin/kibana --config /opt/kibana/config/kibana.yml
Restart=always
StandardOutput=journal
StandardError=journal
ProtectSystem=full

[Install]
WantedBy=multi-user.target
# systemctl daemon-reload
# systemctl enable kibana.service
# systemctl start kibana.service

3.5 Log in to the Kibana dashboard

Access Kibana and configure it
Launch Kibana as the "kibana" user, and use the address displayed in the console: http://192.168.11.85:5601/code=xxxxxxx

# sudo -u kibana /opt/kibana/bin/kibana

If you paste the Enrollment Token into the browser's setup screen and are prompted to generate and enter a verification code, follow the instructions and use the command below to generate the verification code.

# cd /opt/kibana/bin
# ./kibana-verification-code
Your verification code is:  xxx xxx

When you paste the token, Kibana automatically connects to Elasticsearch.
Click "Configure Elastic." The settings are saved, and Elasticsearch is configured and restarted.

You will be redirected to the login page. Log in using the generated Elastic user credentials.
Username : elastic
Password : A password that has been regenerated for ease of understanding

On the welcome page, click “Explore on my own” to go to the Kibana 8.x dashboard.

Create a new user account so that you don't need to use the Elastic superuser account.
Open the main menu and、Stack Management >Security> Users

Click the "Create user" button in the upper-right corner

Enter the new user's information and assign the kibana_admin, kibana_system, monitoring_user, and editor roles under "Privileges."
Finally, click [Create user].

Log out of your current profile and verify that you can log in with the newly created user account. Since Filebeat and Auditbeat are not currently configured on the SURICATA host, there is no data available to view in Kibana.

Install Filebeat on the SURICATA server

1.Download, Extract, and Deploy the Archive

# wget https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-8.19.22-linux-x86_64.tar.gz
# tar -xvf filebeat-8.19.22-linux-x86_64.tar.gz
# mv filebeat-8.19.22-linux-x86_64 /opt/filebeat

2. Elasticsearch CA Certificate
Download the Elasticsearch CA certificate and save it to a directory of your choice (in this example, we'll save it to /opt/filebeat/).
*Make sure to open port 9200 on Server 2 (the server running Elasticsearch).

# scp root@192.168.11.85:/opt/elasticsearch/config/certs/http_ca.crt /opt/filebeat/

3. Symbolic Link (Add "bin" to PATH)

# ln -s /opt/filebeat/filebeat /usr/local/bin/filebeat

4. Verifying the Version and Checking Settings

# filebeat version
filebeat version 8.19.22 (amd64), libbeat 8.19.22 [ada3d02e16d0e102f3a8a6df851b8b382145e02d built 2026-09-18 06:58:39 +0000 UTC] (FIPS-distribution: false)

# filebeat test config -c /opt/filebeat/filebeat.yml
Config OK

5. FConfigure Filebeat to connect to Elasticsearch and Kibana

# vim /opt/filebeat/filebeat.yml

Line 28
filebeat.inputs:
 enabled: true

Add a line below the commented-out line #host: "localhost:5601" on line 141 that specifies the private IP address and port of the Kibana instance.
host: "http://192.168.11.85:5601"

Line 168 : comment
#hosts: ["localhost:9200"]

Line 169 : Enter the IP address of the Elastic Stack and the port number for Elasticsearch
hosts: ["https://192.168.11.85:9200"]

Line 176 : Uncomments
protocol: "https"

Line 177 : Specifying an Elasticsearch CA Certificate
ssl.certificate_authorities: ["/opt/filebeat/elastic-ca.crt"]

Line 180,181 : Uncheck the comment box, leave [username] as the default, and enter the password for the [elastic] user in the [password] field.
username: "elastic"
password: “xxxxxxxxx"

6. Configuration File Test

# filebeat test config -c /opt/filebeat/filebeat.yml
Config OK

7. Enable Filebeats' built-in Suricata module

#  filebeat modules enable suricata -c /opt/filebeat/filebeat.yml
Module suricata is already enabled

The command above will rename /opt/filebeat/modules.d/suricata.yml.disabled to /opt/filebeat/modules.d/suricata.yml, but since the contents remain unchanged, edit it as follows:

# vim /opt/filebeat/modules.d/suricata.yml

# Module: suricata
# Docs: https://www.elastic.co/guide/en/beats/filebeat/main/filebeat-module-suricata.html

- module: suricata
  # All logs
  eve:
    enabled: true
    var.paths: ["/var/log/suricata/eve.json"]

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    #var.paths:

8. Set up the initial environment
Pipeline for the Suricata service
Load the SIEM dashboard into Elasticsearch

# /opt/filebeat/filebeat setup -e -c /opt/filebeat/filebeat.yml

{"log.level":"info","@timestamp":"2026-09-30T15:59:47.996+0900","log.logger":"modules","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/fileset.LoadPipeline","file.name":"fileset/pipelines.go","file.line":135},"message":"Elasticsearch pipeline loaded.","service.name":"filebeat","pipeline":"filebeat-8.19.22-suricata-eve-pipeline","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2026-09-30T15:59:47.999+0900","log.logger":"modules","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/fileset.LoadPipeline","file.name":"fileset/pipelines.go","file.line":135},"message":"Elasticsearch pipeline loaded.","service.name":"filebeat","pipeline":"filebeat-8.19.22-suricata-eve-dns","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2026-09-30T15:59:48.002+0900","log.logger":"modules","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/fileset.LoadPipeline","file.name":"fileset/pipelines.go","file.line":135},"message":"Elasticsearch pipeline loaded.","service.name":"filebeat","pipeline":"filebeat-8.19.22-suricata-eve-dns-answer-v1","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2026-09-30T15:59:48.005+0900","log.logger":"modules","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/fileset.LoadPipeline","file.name":"fileset/pipelines.go","file.line":135},"message":"Elasticsearch pipeline loaded.","service.name":"filebeat","pipeline":"filebeat-8.19.22-suricata-eve-dns-answer-v2","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2026-09-30T15:59:48.007+0900","log.logger":"modules","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/fileset.LoadPipeline","file.name":"fileset/pipelines.go","file.line":135},"message":"Elasticsearch pipeline loaded.","service.name":"filebeat","pipeline":"filebeat-8.19.22-suricata-eve-tls","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2026-09-30T15:59:48.011+0900","log.logger":"modules","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/fileset.LoadPipeline","file.name":"fileset/pipelines.go","file.line":135},"message":"Elasticsearch pipeline loaded.","service.name":"filebeat","pipeline":"filebeat-8.19.22-suricata-eve-http","ecs.version":"1.6.0"}

For further information, please refer to the page below