Log analysis OpenSource con Logstash, Elasticsearch e Kibana
Upcoming SlideShare
Loading in...5
×
 

Log analysis OpenSource con Logstash, Elasticsearch e Kibana

on

  • 3,908 views

Log analysis Open Source con Logstash, Elasticsearch e Kibana. ...

Log analysis Open Source con Logstash, Elasticsearch e Kibana.
A cosa serve la log analysis? Panoramica sulle possibilita' offerte da Logstash, Elasticsearch e Kibana per la gestione centralizzata open source di log.

Statistics

Views

Total Views
3,908
Views on SlideShare
2,320
Embed Views
1,588

Actions

Likes
2
Downloads
32
Comments
0

7 Embeds 1,588

http://www.servermanaged.it 1556
https://twitter.com 24
http://www.linkedin.com 2
http://translate.googleusercontent.com 2
http://131.253.14.66 2
https://www.linkedin.com 1
http://www.google.it 1
More...

Accessibility

Categories

Upload Details

Uploaded via as Adobe PDF

Usage Rights

© All Rights Reserved

Report content

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate.

Cancel
  • Full Name Full Name Comment goes here.
    Are you sure you want to
    Your message goes here
    Processing…
Post Comment
Edit your comment

Log analysis OpenSource con Logstash, Elasticsearch e Kibana Log analysis OpenSource con Logstash, Elasticsearch e Kibana Presentation Transcript

  • #servertraining Log Analysis Open Source con Logstash Elasticsearch & Kibana www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Slides a cura di Valentino Gagliardi Technical Manager at ServerManaged.it Devop & Sysadmin vecchia scuola, consulente informatico per small/medium business, cloud, hosting operations. www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Sommario Log analysis, a cosa serve? ●In principio era... ●Cos'e' Logstash ●Cos'e' Elasticsearch ●Cos'e' Kibana ●The big picture, un setup tipico ●Ma Splunk? E Loggly? ●Logstash, vantaggi ● www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Log analysis: “is an art and science seeking to make sense out of computergenerated records” www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Tradotto: dare un senso ad una montagna di log provenienti da server, routers, ecc www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Log: I registri di un sistema. Se c'e' un problema sul server Y c'e' anche una traccia nei log. www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Log analysis per: - tracciare i problemi - prevenire incidenti di sicurezza - ricostruirli se avvengono www.servermanaged.it twitter.com/servermanagedit
  • #servertraining In principio era tailf ... www.servermanaged.it twitter.com/servermanagedit
  • #servertraining # tailf /var/log/secure www.servermanaged.it twitter.com/servermanagedit
  • #servertraining # tailf /var/log/secure # tailf /var/log/messages www.servermanaged.it twitter.com/servermanagedit
  • #servertraining # tailf /var/log/secure # tailf /var/log/messages # multitail /var/log/httpd/error.log /var/log/httpd/access.log www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Oggi e' data visualization www.servermanaged.it twitter.com/servermanagedit
  • #servertraining www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Cos'e' Logstash? “Logstash helps you take logs and other event data from your systems and store them in a central place. “ www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Logstash: trasforma qualsiasi fonte di eventi e log in qualcosa di digeribile e processabile www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Logstash: 36 inputs (and growing) 14 codecs (and growing) 40 filtri (and growing) 50 outputs (and growing) www.servermanaged.it twitter.com/servermanagedit
  • #servertraining ## Una configurazione minimale di Logstash input { file { type => "linux-syslog" path => ["/var/log/*.log"] exclude => [ "*.gz" ] } } output { redis { host => "127.0.0.1" data_type => "list" key => "syslog" } } ## www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Cos'e' Redis? “Redis is an open source, BSD licensed, advanced key-value store.“ www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Redis: in un sistema di logging centralizzato puo' essere usato come buffer per i log www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Cos'e' Elasticsearch? “flexible and powerful open source, distributed real-time search and analytics engine for the cloud“ www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Elasticsearch: in un sistema di logging centralizzato puo' essere usato come output per indicizzare i log www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Cos'e' Kibana? “Make Sense of your Data“ www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Kibana: una dashboard per estrarre i dati da Elasticsearch www.servermanaged.it twitter.com/servermanagedit
  • #servertraining www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Big picture: logging centralizzato www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Un setup tipico per il logging centralizzato con Rsyslog, Logstash, Redis, Elasticsearch e Kibana. www.servermanaged.it twitter.com/servermanagedit
  • #servertraining server Server di Logging Centralizzato server server rsyslog server www.servermanaged.it twitter.com/servermanagedit
  • #servertraining server Server di Logging Centralizzato server server server rsyslog server server www.servermanaged.it twitter.com/servermanagedit
  • #servertraining server Server di Logging Centralizzato server server server rsyslog server server www.servermanaged.it twitter.com/servermanagedit
  • #servertraining server Server di Logging Centralizzato server server server rsyslog server server www.servermanaged.it twitter.com/servermanagedit
  • #servertraining server Server di Logging Centralizzato server server server rsyslog server server www.servermanaged.it twitter.com/servermanagedit
  • #servertraining server Server di Logging Centralizzato server server server rsyslog server server www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Ok tutto bello. “Ma cosa te ne fai di questi grafici?” (tratto da una domanda vera) www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Centralizzare i log: - visibilita' dei trend - visibilita' dei problemi - analisi di sicurezza www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Caso di studio. Mitigazione di una serie di potenti attacchi bruteforce www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Visualizzare le conseguenze di un attacco, anticipare il trend e mitigare la minaccia. In rosso: attacco bruteforce massivo su siti web Joomla In verde: mitigazione dell'attacco. Le richieste anomale vengono respinte www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Non solo Logstash: Le alternative costose al logging centralizzato open source. www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Splunk> Grab a 20GB license for 12187631461319$/month (gratuito fino a 500MB/giorno) www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Splunk> www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Loggly 10GB di log al giorno con una ritenzione di 90 giorni costano circa 1482 dollari al mese. www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Ogni prodotto ha pro e contro. Splunk e Loggly: compliance e immediatezza. Logstash: per i nerd. www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Logstash: vantaggi - open source - gratuito - una folta community - in continuo sviluppo www.servermanaged.it twitter.com/servermanagedit
  • #servertraining KEEP CALM AND LOGSTASH www.servermanaged.it twitter.com/servermanagedit
  • #servertraining http://www.logstash.net http://www.redis.io http://www.elasticsearch.org www.servermanaged.it twitter.com/servermanagedit
  • #servertraining Slides a cura di Valentino Gagliardi Technical Manager at ServerManaged.it Devop & Sysadmin vecchia scuola, consulente informatico per small/medium business, cloud, hosting operations. (Vieni a trovarmi su Google+, LinkedIn e Twitter) Immagine di sfondo: http://medialoot.com/item/free-dark-noise-backgrounds www.servermanaged.it twitter.com/servermanagedit