ELK stands for:
- Elasticsearch: The one that keeps
- Logstash: The one that guides
- Kibana: The one that shows
Before trying to use this lab, make sure you...:
- Have the
git
command/package installed - Have a functional
docker
environment - Have the
docker-compose
command/package installed
Well...
You need to:
- Download this repository (
git clone https://github.com/fewbits/elk-lab.git
) - Enter the elk-lab directory (
cd elk-lab
) - Review and, if needed, change the docker-compose.yml file to reflect to your needs (
vim docker-compose.yml
) - Run the lab (
docker-compose up -d
)
When using ELK in Production, there are things that must be considered (remember, this is just a lab!):
- Value of
vm.max_map_count
(please refer to https://hub.docker.com/_/elasticsearch/)
- N/A yet
- N/A yet