ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    ELK server is up, now how do I use it.

    IT Discussion
    elk what next
    7
    15
    2.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JaredBuschJ
      JaredBusch
      last edited by

      i have been.

      1 Reply Last reply Reply Quote 2
      • MattSpellerM
        MattSpeller @Dashrender
        last edited by

        @Dashrender said:

        RTFM?

        Blasphemy

        1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller
          last edited by

          You have to select FileBeat and set it to be the default. It won't let you do anything till you do that. Once you do that you can go to the Discover page. At least in theory.

          If that works (it should be blank) then we can start sending in logs. I've got that on the list to get documented. Haven't had a spare moment today but will have that soon(ish).

          JaredBuschJ 1 Reply Last reply Reply Quote 1
          • JaredBuschJ
            JaredBusch @scottalanmiller
            last edited by

            @scottalanmiller said:

            You have to select FileBeat and set it to be the default. It won't let you do anything till you do that. Once you do that you can go to the Discover page. At least in theory.

            If that works (it should be blank) then we can start sending in logs. I've got that on the list to get documented. Haven't had a spare moment today but will have that soon(ish).

            Well, I can also read up on that myself now that I know what it is.

            1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller
              last edited by

              I've got a working filebeat and topbeat process. I'll try to get it up tonight, hopefully.

              A 1 Reply Last reply Reply Quote 0
              • A
                Alex Sage @scottalanmiller
                last edited by Alex Sage

                @scottalanmiller said:

                I'll try to get it up tonight, hopefully.

                Make sure this doesn't get taken out of context, it has a complete different meaning that way. 😆

                1 Reply Last reply Reply Quote 2
                • coliverC
                  coliver
                  last edited by

                  @JaredBusch did you ever get your machines logging to the ELK stack?

                  JaredBuschJ 1 Reply Last reply Reply Quote 2
                  • JaredBuschJ
                    JaredBusch @coliver
                    last edited by

                    @coliver said in ELK server is up, now how do I use it.:

                    @JaredBusch did you ever get your machines logging to the ELK stack?

                    No. I have some half baked setup. I need to spend time on that project.

                    MattSpellerM 1 Reply Last reply Reply Quote 1
                    • MattSpellerM
                      MattSpeller @JaredBusch
                      last edited by

                      @JaredBusch said in ELK server is up, now how do I use it.:

                      @coliver said in ELK server is up, now how do I use it.:

                      @JaredBusch did you ever get your machines logging to the ELK stack?

                      No. I have some half baked setup. I need to spend time on that project.

                      I'm going to have to tackle something very similar later this summer / fall - would highly appreciate any notes or thoughts you have on your journey.

                      Like yourself, I can (probably) follow all SAM's steps to make it chooch but after that I'm a bit lost... I can direct my firewalls to spew logs at it but how do I search them? Make them pretty? Setup alerts for important things?

                      1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller
                        last edited by

                        Searching... that is a MAJOR undertaking in any of these systems. It is exhausting.

                        1 Reply Last reply Reply Quote 0
                        • BRRABillB
                          BRRABill
                          last edited by

                          I was playing a little bit with LOGG.LY today and I think I fried my brain.

                          I'm trying to get my logs off my XS USB boot device see it doesn't get its brain fried.

                          I'll be watching this ELK discussion to see how everyone does.

                          1 Reply Last reply Reply Quote 2
                          • 1 / 1
                          • First post
                            Last post