Welcome to the Suricata app for Splunk.
This app contains field extraction for Suricata fast.log and separate field extraction for Suricata ssh.json log. Suricata ssh.json it's a separate log for only ssh events (all ssh events in your traffic).
Aslo in app you can find two dashboard.
- First dashboard for analysis suricata fast.log
- Second dashboad for visual analisis ssh.json log with function for flexible analysis by next field: data source, source and destination ip, server or client software, time.