@suricata Are there any known tools for storing the #Suricata rules themselves (not the eve logs) in #elastic ?
This might be very useful for the analysts, if you could provide a reference in alerts to the originating rule via its rule id.
Converting the rules to JSON via @ish 's rjs might be a good first step.