ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    ELK server is up, now how do I use it.

    IT Discussion
    elk what next
    7
    15
    2.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JaredBuschJ
      JaredBusch
      last edited by

      Alright, so using Scott's script, i have an ELK server up and running.

      I also popped onto an ownCloud server and setup logstash to ship the basic logs per Scott's other post on that subject.

      Now how do I begin to make use of it?

      When I log in I see this and have no obvious instruction on where to go next.

      0_1456340522497_upload-3ad1d291-c083-492a-ac46-d0791c578b2d

      1 Reply Last reply Reply Quote 6
      • MattSpellerM
        MattSpeller
        last edited by

        All of my upvotes for this post - very curious to see how to harvest and then graph logs from various sources (firewall, servers, UPS units, printers, etc etc)

        1 Reply Last reply Reply Quote 0
        • A
          Alex Sage
          last edited by

          I also need to know this as well 🙂

          1 Reply Last reply Reply Quote 0
          • DashrenderD
            Dashrender
            last edited by Dashrender

            I just have to toss this out there - RTFM?

            😉

            MattSpellerM 1 Reply Last reply Reply Quote 2
            • JaredBuschJ
              JaredBusch
              last edited by

              i have been.

              1 Reply Last reply Reply Quote 2
              • MattSpellerM
                MattSpeller @Dashrender
                last edited by

                @Dashrender said:

                RTFM?

                Blasphemy

                1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller
                  last edited by

                  You have to select FileBeat and set it to be the default. It won't let you do anything till you do that. Once you do that you can go to the Discover page. At least in theory.

                  If that works (it should be blank) then we can start sending in logs. I've got that on the list to get documented. Haven't had a spare moment today but will have that soon(ish).

                  JaredBuschJ 1 Reply Last reply Reply Quote 1
                  • JaredBuschJ
                    JaredBusch @scottalanmiller
                    last edited by

                    @scottalanmiller said:

                    You have to select FileBeat and set it to be the default. It won't let you do anything till you do that. Once you do that you can go to the Discover page. At least in theory.

                    If that works (it should be blank) then we can start sending in logs. I've got that on the list to get documented. Haven't had a spare moment today but will have that soon(ish).

                    Well, I can also read up on that myself now that I know what it is.

                    1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller
                      last edited by

                      I've got a working filebeat and topbeat process. I'll try to get it up tonight, hopefully.

                      A 1 Reply Last reply Reply Quote 0
                      • A
                        Alex Sage @scottalanmiller
                        last edited by Alex Sage

                        @scottalanmiller said:

                        I'll try to get it up tonight, hopefully.

                        Make sure this doesn't get taken out of context, it has a complete different meaning that way. 😆

                        1 Reply Last reply Reply Quote 2
                        • coliverC
                          coliver
                          last edited by

                          @JaredBusch did you ever get your machines logging to the ELK stack?

                          JaredBuschJ 1 Reply Last reply Reply Quote 2
                          • JaredBuschJ
                            JaredBusch @coliver
                            last edited by

                            @coliver said in ELK server is up, now how do I use it.:

                            @JaredBusch did you ever get your machines logging to the ELK stack?

                            No. I have some half baked setup. I need to spend time on that project.

                            MattSpellerM 1 Reply Last reply Reply Quote 1
                            • MattSpellerM
                              MattSpeller @JaredBusch
                              last edited by

                              @JaredBusch said in ELK server is up, now how do I use it.:

                              @coliver said in ELK server is up, now how do I use it.:

                              @JaredBusch did you ever get your machines logging to the ELK stack?

                              No. I have some half baked setup. I need to spend time on that project.

                              I'm going to have to tackle something very similar later this summer / fall - would highly appreciate any notes or thoughts you have on your journey.

                              Like yourself, I can (probably) follow all SAM's steps to make it chooch but after that I'm a bit lost... I can direct my firewalls to spew logs at it but how do I search them? Make them pretty? Setup alerts for important things?

                              1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller
                                last edited by

                                Searching... that is a MAJOR undertaking in any of these systems. It is exhausting.

                                1 Reply Last reply Reply Quote 0
                                • BRRABillB
                                  BRRABill
                                  last edited by

                                  I was playing a little bit with LOGG.LY today and I think I fried my brain.

                                  I'm trying to get my logs off my XS USB boot device see it doesn't get its brain fried.

                                  I'll be watching this ELK discussion to see how everyone does.

                                  1 Reply Last reply Reply Quote 2
                                  • 1 / 1
                                  • First post
                                    Last post