ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    ELK server is up, now how do I use it.

    IT Discussion
    elk what next
    7
    15
    2.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • MattSpellerM
      MattSpeller
      last edited by

      All of my upvotes for this post - very curious to see how to harvest and then graph logs from various sources (firewall, servers, UPS units, printers, etc etc)

      1 Reply Last reply Reply Quote 0
      • A
        Alex Sage
        last edited by

        I also need to know this as well 🙂

        1 Reply Last reply Reply Quote 0
        • DashrenderD
          Dashrender
          last edited by Dashrender

          I just have to toss this out there - RTFM?

          😉

          MattSpellerM 1 Reply Last reply Reply Quote 2
          • JaredBuschJ
            JaredBusch
            last edited by

            i have been.

            1 Reply Last reply Reply Quote 2
            • MattSpellerM
              MattSpeller @Dashrender
              last edited by

              @Dashrender said:

              RTFM?

              Blasphemy

              1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller
                last edited by

                You have to select FileBeat and set it to be the default. It won't let you do anything till you do that. Once you do that you can go to the Discover page. At least in theory.

                If that works (it should be blank) then we can start sending in logs. I've got that on the list to get documented. Haven't had a spare moment today but will have that soon(ish).

                JaredBuschJ 1 Reply Last reply Reply Quote 1
                • JaredBuschJ
                  JaredBusch @scottalanmiller
                  last edited by

                  @scottalanmiller said:

                  You have to select FileBeat and set it to be the default. It won't let you do anything till you do that. Once you do that you can go to the Discover page. At least in theory.

                  If that works (it should be blank) then we can start sending in logs. I've got that on the list to get documented. Haven't had a spare moment today but will have that soon(ish).

                  Well, I can also read up on that myself now that I know what it is.

                  1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller
                    last edited by

                    I've got a working filebeat and topbeat process. I'll try to get it up tonight, hopefully.

                    A 1 Reply Last reply Reply Quote 0
                    • A
                      Alex Sage @scottalanmiller
                      last edited by Alex Sage

                      @scottalanmiller said:

                      I'll try to get it up tonight, hopefully.

                      Make sure this doesn't get taken out of context, it has a complete different meaning that way. 😆

                      1 Reply Last reply Reply Quote 2
                      • coliverC
                        coliver
                        last edited by

                        @JaredBusch did you ever get your machines logging to the ELK stack?

                        JaredBuschJ 1 Reply Last reply Reply Quote 2
                        • JaredBuschJ
                          JaredBusch @coliver
                          last edited by

                          @coliver said in ELK server is up, now how do I use it.:

                          @JaredBusch did you ever get your machines logging to the ELK stack?

                          No. I have some half baked setup. I need to spend time on that project.

                          MattSpellerM 1 Reply Last reply Reply Quote 1
                          • MattSpellerM
                            MattSpeller @JaredBusch
                            last edited by

                            @JaredBusch said in ELK server is up, now how do I use it.:

                            @coliver said in ELK server is up, now how do I use it.:

                            @JaredBusch did you ever get your machines logging to the ELK stack?

                            No. I have some half baked setup. I need to spend time on that project.

                            I'm going to have to tackle something very similar later this summer / fall - would highly appreciate any notes or thoughts you have on your journey.

                            Like yourself, I can (probably) follow all SAM's steps to make it chooch but after that I'm a bit lost... I can direct my firewalls to spew logs at it but how do I search them? Make them pretty? Setup alerts for important things?

                            1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller
                              last edited by

                              Searching... that is a MAJOR undertaking in any of these systems. It is exhausting.

                              1 Reply Last reply Reply Quote 0
                              • BRRABillB
                                BRRABill
                                last edited by

                                I was playing a little bit with LOGG.LY today and I think I fried my brain.

                                I'm trying to get my logs off my XS USB boot device see it doesn't get its brain fried.

                                I'll be watching this ELK discussion to see how everyone does.

                                1 Reply Last reply Reply Quote 2
                                • 1 / 1
                                • First post
                                  Last post