Closed hartescout closed 3 years ago
Hey @hartescout ! Quick question. I can see the Filebeat establishing a connection to Kafka. however, I do not see any log saying that it was able to send any logs right?
If it is actually sending logs, did you check all the indices from this output config? https://github.com/Cyb3rWard0g/HELK/blob/ebf25b5d2d04603af49258c789f4d72ab23c5e98/docker/helk-logstash/pipeline/9998-catch_all-output.conf
I wonder if it is in the indexme-* indices. maybe?
I think that might be the issue. I haven't looked at the conf or indexme-* indices. I'll take a look and update. Thanks for the help!
@Cyb3rWard0g Hey thanks for the help so far. Here is the readout from the first "indexme-*" search I did on the machine running HELK. I have not altered anything in any other files besides filebeat.yml
I'll keep tooling around. Hope this helps, let me know if you need any more output/data!
edit: Shoot, I just notice the password is default, 'elasticpassword'. Would I need to change that to what I configured when asked during install?
` # Not in schema yet else if [@metadata][helk_parsed] != "yes" and [source] != "/var/log/osquery/osqueryd.results.log" and [@metadat$
if [event_log] == "zeek" {
elasticsearch {
hosts => ["helk-elasticsearch:9200"]
index => "indexme-zeek-%{+YYYY.MM.dd}"
# document_id => "%{[@metadata][log_hash]}"
user => 'elastic'
#password => 'elasticpassword'
}
`
the password line is a comment and does not apply to it. You mentioned that you were sharing the output of filebeat saying it connected properly witth the kafka broker from HELK. do you have that screenshot? I want to make sure the problem is not from Client -> HELK(Kafka broker) and not the pipeline itself.
I still owe you an answer. I'll get that too you soon. Away from desk for a couple days.
no response - closing
Describe the problem
I am unable to read data from Zeek 3.2.0 running on Ubuntu 18.04. Zeek filebeat from repo looks to be connecting and pushing data. It's not visualizing. I probably am missing a setting in Kibana, but can't figure it out. Zeek filebeat module enabled and configured to correct log directory. Most likely code in filebeat.yml?
Winlogbeat.yml is pushing Sysmon logs just fine from my other endpoints with same minimal filebeat.yml.
HELK install on a Linode instance 6 cores shared, 16gb ram.
Provide the output of the following commands
Filebeat.yml
Output of filebeat - e