Navigation

    ML
    • Register
    • Login
    • Search
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups

    ELK server is up, now how do I use it.

    IT Discussion
    elk what next
    7
    15
    2021
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JaredBusch
      JaredBusch last edited by

      Alright, so using Scott's script, i have an ELK server up and running.

      I also popped onto an ownCloud server and setup logstash to ship the basic logs per Scott's other post on that subject.

      Now how do I begin to make use of it?

      When I log in I see this and have no obvious instruction on where to go next.

      0_1456340522497_upload-3ad1d291-c083-492a-ac46-d0791c578b2d

      1 Reply Last reply Reply Quote 6
      • MattSpeller
        MattSpeller last edited by

        All of my upvotes for this post - very curious to see how to harvest and then graph logs from various sources (firewall, servers, UPS units, printers, etc etc)

        1 Reply Last reply Reply Quote 0
        • A
          Alex Sage last edited by

          I also need to know this as well :)

          1 Reply Last reply Reply Quote 0
          • Dashrender
            Dashrender last edited by Dashrender

            I just have to toss this out there - RTFM?

            ;)

            MattSpeller 1 Reply Last reply Reply Quote 2
            • JaredBusch
              JaredBusch last edited by

              i have been.

              1 Reply Last reply Reply Quote 2
              • MattSpeller
                MattSpeller @Dashrender last edited by

                @Dashrender said:

                RTFM?

                Blasphemy

                1 Reply Last reply Reply Quote 0
                • scottalanmiller
                  scottalanmiller last edited by

                  You have to select FileBeat and set it to be the default. It won't let you do anything till you do that. Once you do that you can go to the Discover page. At least in theory.

                  If that works (it should be blank) then we can start sending in logs. I've got that on the list to get documented. Haven't had a spare moment today but will have that soon(ish).

                  JaredBusch 1 Reply Last reply Reply Quote 1
                  • JaredBusch
                    JaredBusch @scottalanmiller last edited by

                    @scottalanmiller said:

                    You have to select FileBeat and set it to be the default. It won't let you do anything till you do that. Once you do that you can go to the Discover page. At least in theory.

                    If that works (it should be blank) then we can start sending in logs. I've got that on the list to get documented. Haven't had a spare moment today but will have that soon(ish).

                    Well, I can also read up on that myself now that I know what it is.

                    1 Reply Last reply Reply Quote 0
                    • scottalanmiller
                      scottalanmiller last edited by

                      I've got a working filebeat and topbeat process. I'll try to get it up tonight, hopefully.

                      A 1 Reply Last reply Reply Quote 0
                      • A
                        Alex Sage @scottalanmiller last edited by Alex Sage

                        @scottalanmiller said:

                        I'll try to get it up tonight, hopefully.

                        Make sure this doesn't get taken out of context, it has a complete different meaning that way. :laughing:

                        1 Reply Last reply Reply Quote 2
                        • coliver
                          coliver last edited by

                          @JaredBusch did you ever get your machines logging to the ELK stack?

                          JaredBusch 1 Reply Last reply Reply Quote 2
                          • JaredBusch
                            JaredBusch @coliver last edited by

                            @coliver said in ELK server is up, now how do I use it.:

                            @JaredBusch did you ever get your machines logging to the ELK stack?

                            No. I have some half baked setup. I need to spend time on that project.

                            MattSpeller 1 Reply Last reply Reply Quote 1
                            • MattSpeller
                              MattSpeller @JaredBusch last edited by

                              @JaredBusch said in ELK server is up, now how do I use it.:

                              @coliver said in ELK server is up, now how do I use it.:

                              @JaredBusch did you ever get your machines logging to the ELK stack?

                              No. I have some half baked setup. I need to spend time on that project.

                              I'm going to have to tackle something very similar later this summer / fall - would highly appreciate any notes or thoughts you have on your journey.

                              Like yourself, I can (probably) follow all SAM's steps to make it chooch but after that I'm a bit lost... I can direct my firewalls to spew logs at it but how do I search them? Make them pretty? Setup alerts for important things?

                              1 Reply Last reply Reply Quote 0
                              • scottalanmiller
                                scottalanmiller last edited by

                                Searching... that is a MAJOR undertaking in any of these systems. It is exhausting.

                                1 Reply Last reply Reply Quote 0
                                • BRRABill
                                  BRRABill last edited by

                                  I was playing a little bit with LOGG.LY today and I think I fried my brain.

                                  I'm trying to get my logs off my XS USB boot device see it doesn't get its brain fried.

                                  I'll be watching this ELK discussion to see how everyone does.

                                  1 Reply Last reply Reply Quote 2
                                  • First post
                                    Last post