{"id":1702,"date":"2017-07-25T16:25:01","date_gmt":"2017-07-25T13:25:01","guid":{"rendered":"https:\/\/www.artifex.co.il\/he\/?p=1702"},"modified":"2017-07-25T16:25:01","modified_gmt":"2017-07-25T13:25:01","slug":"%d7%94%d7%aa%d7%a7%d7%a0%d7%aa-elk-%d7%90%d7%95-%d7%91%d7%a9%d7%9e%d7%95-%d7%94%d7%97%d7%93%d7%a9-elastic-stack-%d7%94-cheat-sheet","status":"publish","type":"post","link":"https:\/\/www.artifex.co.il\/he\/?p=1702","title":{"rendered":"\u05d4\u05ea\u05e7\u05e0\u05ea ELK (\u05d0\u05d5 \u05d1\u05e9\u05de\u05d5 \u05d4\u05d7\u05d3\u05e9 Elastic-Stack) &#8211; \u05d4-Cheat Sheet"},"content":{"rendered":"<p>\u05e2\u05dc \u05de\u05e0\u05ea \u05dc\u05d4\u05ea\u05e7\u05d9\u05df \u05d0\u05ea Elasticsearch, Logstash, Kibana \u05d5\u05dc\u05e9\u05dc\u05d5\u05d7 \u05dc\u05d5\u05d2\u05d9\u05dd \u05de-Windows \u05e2\u05dc \u05d1\u05e1\u05d9\u05e1 NXLOG \u05d5-Sysmon \u05d9\u05e9 \u05dc\u05d1\u05e6\u05e2 \u05d0\u05ea \u05d4\u05e9\u05dc\u05d1\u05d9\u05dd \u05d4\u05d1\u05d0\u05d9\u05dd:<\/p>\n<p style=\"direction: ltr;\"># On a fresh Ubuntu 16.04 server VM with at least 4GB RAM<br \/>\n# Refresh the APT cache<br \/>\nsudo apt-get update<\/p>\n<p dir=\"ltr\"># Install default Java runtime<br \/>\nsudo apt-get install default-jre<\/p>\n<p dir=\"ltr\"># Download all the components<br \/>\nwget\u00a0https:\/\/artifacts.elastic.co\/downloads\/logstash\/logstash-5.5.0.deb<br \/>\nwget\u00a0https:\/\/artifacts.elastic.co\/downloads\/elasticsearch\/elasticsearch-5.5.0.deb<br \/>\nwget\u00a0https:\/\/artifacts.elastic.co\/downloads\/kibana\/kibana-5.5.0-amd64.deb<\/p>\n<p dir=\"ltr\"># Install all components<br \/>\nsudo dpkg -i\u00a0logstash-5.5.0.deb<br \/>\nsudo dpkg -i\u00a0elasticsearch-5.5.0.deb<br \/>\nsudo dpkg -i\u00a0kibana-5.5.0-amd64.deb<\/p>\n<p dir=\"ltr\"># Configure kibana to listen on 0.0.0.0 (all interfaces)<br \/>\n# Replace the line '#server: &quot;localhost&quot;' to 'server: &quot;0.0.0.0&quot;'<br \/>\nsudo nano \/etc\/kibana\/kibana.yml<\/p>\n<p dir=\"ltr\"># Enable services<br \/>\nsudo systemctl enable\u00a0kibana<br \/>\nsudo systemctl enable elasticsearch<br \/>\nsudo systemctl enable logstash<\/p>\n<p dir=\"ltr\"># Configure logstash to listen on 5555\/tcp<br \/>\necho '<br \/>\ninput {<br \/>\ntcp {<br \/>\nport =&gt; 5555<br \/>\n}<br \/>\n}<br \/>\noutput {<br \/>\nelasticsearch {<br \/>\n}<br \/>\n}' | sudo tee \/etc\/logstash\/conf.d\/logstash.config<\/p>\n<p dir=\"ltr\"># On a fresh Windows machine download and install NXLOG &#8211;\u00a0https:\/\/nxlog.co\/system\/files\/products\/files\/1\/nxlog-ce-2.9.1716.msi<br \/>\n# Configure NXLOG by writing the following into the C:\\Program Files (x86)\\nxlog\\conf\\nxlog.conf file:<\/p>\n<p dir=\"ltr\">## This is a sample configuration file. See the nxlog reference manual about the<br \/>\n## configuration options. It should be installed locally and is also available<br \/>\n## online at http:\/\/nxlog.org\/docs\/<\/p>\n<p dir=\"ltr\">## Please set the ROOT to the folder your nxlog was installed into,<br \/>\n## otherwise it will not start.<\/p>\n<p dir=\"ltr\">define ROOT C:\\Program Files\\nxlog<br \/>\n#define ROOT C:\\Program Files (x86)\\nxlog<\/p>\n<p dir=\"ltr\">Moduledir %ROOT%\\modules<br \/>\nCacheDir %ROOT%\\data<br \/>\nPidfile %ROOT%\\data\\nxlog.pid<br \/>\nSpoolDir %ROOT%\\data<br \/>\nLogFile %ROOT%\\data\\nxlog.log<\/p>\n<p dir=\"ltr\">&lt;Extension _syslog&gt;<br \/>\nModule xm_syslog<br \/>\n&lt;\/Extension&gt;<\/p>\n<p dir=\"ltr\">&lt;Input in&gt;<br \/>\nModule im_msvistalog<br \/>\n# For windows 2003 and earlier use the following:<br \/>\n# Module im_mseventlog<br \/>\n&lt;\/Input&gt;<\/p>\n<p dir=\"ltr\">&lt;Output out&gt;<br \/>\nModule om_tcp<br \/>\nHost 192.168.243.128<br \/>\nPort 5555<br \/>\n# Exec to_syslog_snare();<br \/>\n&lt;\/Output&gt;<\/p>\n<p dir=\"ltr\">&lt;Route 1&gt;<br \/>\nPath in =&gt; out<br \/>\n&lt;\/Route&gt;<\/p>\n<p dir=\"ltr\"># Start the nxlog service via services.msc<\/p>\n<p>\u05e7\u05d9\u05e9\u05d5\u05e8\u05d9\u05dd \u05e9\u05d9\u05de\u05d5\u05e9\u05d9\u05d9\u05dd:<\/p>\n<p><a href=\"https:\/\/www.elastic.co\/guide\/en\/logstash\/current\/output-plugins.html\">https:\/\/www.elastic.co\/guide\/en\/logstash\/current\/output-plugins.html<\/a> &#8211; \u05e4\u05d9\u05e8\u05d5\u05d8 \u05dc\u05d2\u05d1\u05d9 \u05d4-Output plugins \u05e9-Logstash \u05de\u05db\u05d9\u05e8<\/p>\n<p><a href=\"https:\/\/www.elastic.co\/guide\/en\/logstash\/current\/input-plugins.html\">https:\/\/www.elastic.co\/guide\/en\/logstash\/current\/input-plugins.html<\/a> &#8211; \u05e4\u05d9\u05e8\u05d5\u05d8 \u05dc\u05d2\u05d1\u05d9 \u05d4-Input plugins \u05e9-Logstash \u05de\u05db\u05d9\u05e8<\/p>\n<p><a href=\"https:\/\/grokdebug.herokuapp.com\/\">https:\/\/grokdebug.herokuapp.com\/ <\/a>&#8211; \u05d0\u05ea\u05e8 \u05de\u05e6\u05d5\u05d9\u05d9\u05df \u05dc\u05d1\u05d3\u05d9\u05e7\u05ea Grok Expressions<\/p>\n<p><a href=\"https:\/\/nxlog.co\/docs\/nxlog-ce\/nxlog-reference-manual.pdf\">https:\/\/nxlog.co\/docs\/nxlog-ce\/nxlog-reference-manual.pdf<\/a>\u00a0&#8211; \u05de\u05d0\u05de\u05e8 \u05e2\u05dc \u05d4\u05e4\u05e8\u05de\u05d8\u05e8\u05d9\u05dd \u05d4\u05e7\u05d9\u05d9\u05de\u05d9\u05dd \u05d1-NXLOG<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u05e2\u05dc \u05de\u05e0\u05ea \u05dc\u05d4\u05ea\u05e7\u05d9\u05df \u05d0\u05ea Elasticsearch, Logstash, Kibana \u05d5\u05dc\u05e9\u05dc\u05d5\u05d7 \u05dc\u05d5\u05d2\u05d9\u05dd \u05de-Windows \u05e2\u05dc \u05d1\u05e1\u05d9\u05e1 NXLOG \u05d5-Sysmon \u05d9\u05e9 \u05dc\u05d1\u05e6\u05e2 \u05d0\u05ea \u05d4\u05e9\u05dc\u05d1\u05d9\u05dd \u05d4\u05d1\u05d0\u05d9\u05dd: # On a fresh Ubuntu 16.04 server VM with at least 4GB RAM # Refresh the APT cache sudo apt-get update # Install default Java runtime sudo apt-get install default-jre # &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[1],"tags":[],"class_list":["post-1702","post","type-post","status-publish","format-standard","hentry","category-1"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p785UE-rs","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/www.artifex.co.il\/he\/index.php?rest_route=\/wp\/v2\/posts\/1702","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.artifex.co.il\/he\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.artifex.co.il\/he\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.artifex.co.il\/he\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.artifex.co.il\/he\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1702"}],"version-history":[{"count":3,"href":"https:\/\/www.artifex.co.il\/he\/index.php?rest_route=\/wp\/v2\/posts\/1702\/revisions"}],"predecessor-version":[{"id":1706,"href":"https:\/\/www.artifex.co.il\/he\/index.php?rest_route=\/wp\/v2\/posts\/1702\/revisions\/1706"}],"wp:attachment":[{"href":"https:\/\/www.artifex.co.il\/he\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1702"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.artifex.co.il\/he\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1702"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.artifex.co.il\/he\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1702"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}