ELK stack Elastisearch kibana filebeat netflow
Instalacia:
apt install gnupg2
wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo apt-key add -
sudo apt-get update
sudo apt-get install apt-transport-https
echo "deb https://artifacts.elastic.co/packages/7.x/apt stable main" | sudo tee -a /etc/apt/sources.list.d/elastic-7.x.list
sudo apt-get update
sudo apt-get install elasticsearchUprava konfigu elasticsearch:
nano /etc/elasticsearch/elasticsearch.ymlnetwork.host: "localhost"
http.port:9200
cluster.initial_master_nodes: ["<PrivateIP"]Uprava config:
nano /etc/elasticsearch/jvm.options-Xms8g
-Xmx8gŠtart služby
systemctl enable elasticsearch
systemctl start elasticsearchInstalacia kibana:
sudo apt-get install kibananano /etc/kibana/kibana.ymlserver.port: 5601
elasticsearch.url: "http://localhost:9200"Zapnutie kibana:
systemctl enable kibana
systemctl start kibanaFilebeat install:
curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-7.9.1-amd64.deb
sudo dpkg -i filebeat-7.9.1-amd64.debPovolenie netflow:
sudo filebeat modules enable netflowsystemctl enable filebeat.service
systemctl start filebeat.serviceNastavenie adresy kde nacuva netflow
 nano /etc/filebeat/modules.d/netflow.ymlnetflow_host:Instalovanie filebeat do kibany
filebeat setup