FORENSIC	
  INSIGHT;	
  
DIGITAL	
  FORENSICS	
  COMMUNITY	
  IN	
  KOREA
ELK Forensics
demantos	
  
demantos@gmail.com	
  
http://malwarel4b.blogspot.kr	
  
Cho	
  Hoon
forensicinsight.org Page	
  
Table of Contents
2
▪ Introduction
 
▪ How
 It
 Works
 
▪ Logstash
 
▪ Elasticsearch
 
▪ Kibana
 
▪ ELK
 for
 Analysis
 
▪ ELK
 for
 Windows
 Event
 Log
 
▪ Performance
 Test
 
▪ Future
 Work
 
▪ Reference
 
▪ QA
forensicinsight.org Page	
  
Introduction
3
forensicinsight.org Page	
  
Introduction
4
forensicinsight.org Page	
  
How It Works
5
Logstash ElasticSearch Kibana
•web
 log
 (apache,
 iis,
 …⋯)
 
•mail
 log
 
•mactime
 
•microsoft
 event
 log
 
•syslog
 
•plaso
 
•supertimeline
 
•and
 more
•grok
 
•date
 
•geoip

(Fios#02) 2. elk 포렌식 분석