ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    ELK server is up, now how do I use it.

    IT Discussion
    elk what next
    7
    15
    2.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • MattSpellerM
      MattSpeller @Dashrender
      last edited by

      @Dashrender said:

      RTFM?

      Blasphemy

      1 Reply Last reply Reply Quote 0
      • scottalanmillerS
        scottalanmiller
        last edited by

        You have to select FileBeat and set it to be the default. It won't let you do anything till you do that. Once you do that you can go to the Discover page. At least in theory.

        If that works (it should be blank) then we can start sending in logs. I've got that on the list to get documented. Haven't had a spare moment today but will have that soon(ish).

        JaredBuschJ 1 Reply Last reply Reply Quote 1
        • JaredBuschJ
          JaredBusch @scottalanmiller
          last edited by

          @scottalanmiller said:

          You have to select FileBeat and set it to be the default. It won't let you do anything till you do that. Once you do that you can go to the Discover page. At least in theory.

          If that works (it should be blank) then we can start sending in logs. I've got that on the list to get documented. Haven't had a spare moment today but will have that soon(ish).

          Well, I can also read up on that myself now that I know what it is.

          1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller
            last edited by

            I've got a working filebeat and topbeat process. I'll try to get it up tonight, hopefully.

            A 1 Reply Last reply Reply Quote 0
            • A
              Alex Sage @scottalanmiller
              last edited by Alex Sage

              @scottalanmiller said:

              I'll try to get it up tonight, hopefully.

              Make sure this doesn't get taken out of context, it has a complete different meaning that way. 😆

              1 Reply Last reply Reply Quote 2
              • coliverC
                coliver
                last edited by

                @JaredBusch did you ever get your machines logging to the ELK stack?

                JaredBuschJ 1 Reply Last reply Reply Quote 2
                • JaredBuschJ
                  JaredBusch @coliver
                  last edited by

                  @coliver said in ELK server is up, now how do I use it.:

                  @JaredBusch did you ever get your machines logging to the ELK stack?

                  No. I have some half baked setup. I need to spend time on that project.

                  MattSpellerM 1 Reply Last reply Reply Quote 1
                  • MattSpellerM
                    MattSpeller @JaredBusch
                    last edited by

                    @JaredBusch said in ELK server is up, now how do I use it.:

                    @coliver said in ELK server is up, now how do I use it.:

                    @JaredBusch did you ever get your machines logging to the ELK stack?

                    No. I have some half baked setup. I need to spend time on that project.

                    I'm going to have to tackle something very similar later this summer / fall - would highly appreciate any notes or thoughts you have on your journey.

                    Like yourself, I can (probably) follow all SAM's steps to make it chooch but after that I'm a bit lost... I can direct my firewalls to spew logs at it but how do I search them? Make them pretty? Setup alerts for important things?

                    1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller
                      last edited by

                      Searching... that is a MAJOR undertaking in any of these systems. It is exhausting.

                      1 Reply Last reply Reply Quote 0
                      • BRRABillB
                        BRRABill
                        last edited by

                        I was playing a little bit with LOGG.LY today and I think I fried my brain.

                        I'm trying to get my logs off my XS USB boot device see it doesn't get its brain fried.

                        I'll be watching this ELK discussion to see how everyone does.

                        1 Reply Last reply Reply Quote 2
                        • 1 / 1
                        • First post
                          Last post