evebox v0.11.1 releases: Web Based Event Viewer for Suricata EVE Events
EveBox is a web-based Suricata “eve” event viewer for Elastic Search.
- A web-based event viewer with an “Inbox” approach to alert management.
- Event search.
- An agent for sending Suricata events to the EveBox server (but you can use Filebeat/Logstash instead).
- Embedded SQLite for self-contained installations.
- Handle Filebeat overriding the “host” field with its own object by
normalizing the sensor name before rendering. If Filebeat is used,
the Suricata provided sensor name is lost, so use the Filebeat
esimportto read from multiple eve files. If bookmarking is
--bookmark-dirmust be used instead of
- Support Elastic
Search 7. #112
- Reduce the amount of per minute logs by moving some message to debug
(verbose) mode. #116
- Show event services on first click through to event, rather than having
to refresh to see them.
- Fix sensor name display when event is clicked on in inbox or alert
esimportnow uses a default index of
eveboxto match common usage.
eveboxapplication now requires a command name. It will not
fallback to the server command anymore.
- The EveBox server will now bind to localhost by default instead of
being open. Use the
--hostcommand line option to accept connections
more openly. #110
- GitHub authentication has been removed. Looks like its been broken for
a little while now.
- Filebeat: The basic views work with Filebeat indices but searching
does not. This is due to Filebeat indexing fields as keywords which
complicates “free text” searching. This will probably not be fixed,
but instead focus will be on supporting Elastic Search ECS (or more
simply the Suricata plugin for filebeat) –
- LetsEncrypt support: This is better done by a reverse proxy where
LetsEncrypt support is more of a design goal.
- Plain Filebeat indices will likely be deprecated due to issues with
Copyright (c) 2014-2016 Jason Ish
All rights reserved.