While some IDS/IPS systems still wait for upgrade to Snort3 where JSON logging is available (or Suricata) it may be useful give elasticity of logs handling given by Elasticsearch and Grafana for Snort2
...
...
@@ -12,7 +12,7 @@ Logs flow and components:

Example dashboards:
<h4>Example dashboards:</h4>

...
...
@@ -36,7 +36,7 @@ Output for snort log is set to elasticsearch and index name like snortids-%YY-%M