Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Ossec and LOGSTASH, Kibana

Shulou Source: shulou.com Published: 2022-06-01 04:42:46 10月05日 Update

Configure OSSEC SYSLOG output (all agent)

Edit the ossec.conf file (default is / var/ossec/etc/ossec.conf)

Add the following to ossec.conf (10.0.0.1 is the server that receives the syslog)

10.0.0.1 9000 default

Enable OSSEC to allow syslog output

/ var/ossec/bin/ossec-control enable client-syslog

Restart the OSSEC service

/ var/ossec/bin/ossec-control start configure LOGSTASH

Add (or create) the following to the configuration file in logstash: (suppose 10.0.0.1 is the ES server, and the file name is logstash-ossec.conf)

Input {udp {port = > 9000 type = > "syslog"} filter {if [type] = = "syslog" {grok {match = > {"message" = > "% {SYSLOGTIMESTAMP:syslog_timestamp}% {SYSLOGHOST:syslog_host}% {DATA:syslog_program}: Alert Level:% {BASE10NUM:Alert_Level}; Rule:% {BASE10NUM:Rule} -% {GREEDYDATA:Description} Location:% {GREEDYDATA:Details} "} add_field = > [" ossec_server ","% {host} "]} mutate {remove_field = > [" syslog_hostname "," syslog_message "," syslog_pid "," message "," @ version "," type " "host"]}} output {elasticsearch_http {host = > "10.0.0.1"}} recommended Kibana dashboard

According to the common needs of ossec, some people in the community have made dashboard that can be loaded and used directly from Kibana3 pages.

Tags: Files services configuration content servers outputs features common community requirements pages production recommendations Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno macOS OPPO Reno Redmi Docker Linux