I've added patterns for parsing Suricata HTTP logs properly into
fields in ELSA, but you'll have to forward them using syslog.  This is
really easy with either syslog-ng (using the file() source) or rsyslog
(using $InputFileName).  In both cases, set the program to "url" and
they'll parse into all the right fields so you can do searches like
+referer:showthread.php +user_agent:java
and then report on the IP addresses, dates, sites, etc.

