-
Notifications
You must be signed in to change notification settings - Fork 4
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
Jose Antonio izquierdo lopez
committed
Oct 28, 2020
1 parent
7e5b19e
commit c960907
Showing
25 changed files
with
1,776 additions
and
9 deletions.
There are no files selected for viewing
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,6 +1,6 @@ | ||
|
||
Sync with ELK 7.x | ||
================= | ||
Sync with ELK 7.x using Wazuh | ||
============================= | ||
|
||
.. warning:: | ||
|
||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,107 @@ | ||
|
||
Sync with ELK 7.x | ||
================= | ||
|
||
.. warning:: | ||
|
||
Be sure you are running ELK (elasticsearch, filebeat and kibana) with version >7.3.2 | ||
|
||
.. include:: keepincontact.rst | ||
|
||
This process will allow you to connect your OwlH environment directly to ELK. | ||
|
||
You will do: | ||
|
||
* install filebeat on OwlH Nodes | ||
* install OwlH-Filebeat module | ||
* import OwlH-Kibana objects in Kibana | ||
* load OwlH template in Elasticsearch | ||
* modify Filebeat main configuration to include OwlH module | ||
|
||
|
||
.. note:: | ||
Please, check URLs and paths to ensure you use the right commands and that you adapt command lines as needed. | ||
|
||
|
||
Install Filebeat in your OwlH Nodes | ||
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ | ||
|
||
#. Import the GPG key: | ||
|
||
.. code-block:: console | ||
# rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch | ||
#. Add the repository: | ||
|
||
.. code-block:: console | ||
# cat > /etc/yum.repos.d/elastic.repo << EOF | ||
[elasticsearch-7.x] | ||
name=Elasticsearch repository for 7.x packages | ||
baseurl=https://artifacts.elastic.co/packages/7.x/yum | ||
gpgcheck=1 | ||
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch | ||
enabled=1 | ||
autorefresh=1 | ||
type=rpm-md | ||
EOF | ||
#. Install Filebeat | ||
|
||
.. code-block:: console | ||
# yum install filebeat | ||
Download and configure | ||
^^^^^^^^^^^^^^^^^^^^^^ | ||
|
||
:: | ||
# cd /tmp | ||
# mkdir /tmp/owlhfilebeat | ||
# cd /tmp/owlhfilebeat | ||
# wget repo.owlh.net/fbit/owlh-module.tar.gz | ||
# tar -C /tmp/owlhfilebeat -xf owlh-module.tar.gz | ||
|
||
|
||
Install OwlH module | ||
------------------- | ||
|
||
:: | ||
|
||
# tar -C /usr/share/filebeat/module/ -xf /tmp/owlhfilebeat/owlh-filebeat-7.9.x.tar.gz | ||
|
||
|
||
Modify filebeat | ||
^^^^^^^^^^^^^^^ | ||
|
||
Modify Filebeat configuration | ||
----------------------------- | ||
|
||
:: | ||
|
||
# cp /tmp/owlhfilebeat/filebeat.yml /etc/filebeat/filebeat.yml | ||
|
||
.. attention:: | ||
be sure to update properly your filebeat.yml file to point to your elasticsearch server. | ||
|
||
|
||
|
||
Restart Filebeat | ||
---------------- | ||
|
||
You should be done. check your kibana to see the OwlH dashboards in dashboards section, and indices in discovery section. | ||
|
||
:: | ||
|
||
Restart Filebeat | ||
|
||
# systemctl restart filebeat | ||
|
||
Check Filebeat output | ||
|
||
# journalctl -f -u filebeat | ||
|
||
From your web browser, check kibana->discovery for owlh indices. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,24 @@ | ||
.. Copyright (C) 2020 OwlH. | ||
#. Import the GPG key: | ||
|
||
.. code-block:: console | ||
# rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch | ||
#. Add the repository: | ||
|
||
.. code-block:: console | ||
# cat > /etc/yum.repos.d/elastic.repo << EOF | ||
[elasticsearch-7.x] | ||
name=Elasticsearch repository for 7.x packages | ||
baseurl=https://artifacts.elastic.co/packages/7.x/yum | ||
gpgcheck=1 | ||
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch | ||
enabled=1 | ||
autorefresh=1 | ||
type=rpm-md | ||
EOF | ||
.. End of include file |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,24 @@ | ||
.. Copyright (C) 2020 OwlH. | ||
#. Import the GPG key: | ||
|
||
.. code-block:: console | ||
# rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch | ||
#. Add the repository: | ||
|
||
.. code-block:: console | ||
# cat > /etc/yum.repos.d/elastic.repo << EOF | ||
[elasticsearch-7.x] | ||
name=Elasticsearch repository for 7.x packages | ||
baseurl=https://artifacts.elastic.co/packages/7.x/yum | ||
gpgcheck=1 | ||
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch | ||
enabled=1 | ||
autorefresh=1 | ||
type=rpm-md | ||
EOF | ||
.. End of include file |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,24 @@ | ||
.. Copyright (C) 2020 OwlH. | ||
#. Import the GPG key: | ||
|
||
.. code-block:: console | ||
# rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch | ||
#. Add the repository: | ||
|
||
.. code-block:: console | ||
# cat > /etc/yum.repos.d/elastic.repo << EOF | ||
[elasticsearch-7.x] | ||
name=Elasticsearch repository for 7.x packages | ||
baseurl=https://artifacts.elastic.co/packages/7.x/yum | ||
gpgcheck=1 | ||
gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch | ||
enabled=1 | ||
autorefresh=1 | ||
type=rpm-md | ||
EOF | ||
.. End of include file |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.