cyberdefenders / DetectionLabELK

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.
MIT License
537 stars 101 forks source link

Added Security features into ELK #5

Closed webhead404 closed 3 years ago

webhead404 commented 3 years ago

Adds the required configuration changes needed to have security features such as role based access and the new Detection Rules engine.

webhead404 commented 3 years ago

Will have to pull out the elastic password and put the user required configurations in Winlogbeat and Filebeat. Might be better to write the password file to a directory accessible to all VM's