Logstash - Suricata DNS and fast.log
input { file { path => [ "/mnt/logs/ids/dns.log" ] sincedb_path => "/dev/null" start_position => "beginning" #Поменять на end# tags => ["dns"] } file { path => [ "/mnt/logs/ids/fast.log" ] sincedb_path => "/dev/null" start_position => "beginning" #Поменять на end# tags => ["ids"] }