Security Event Monitoring,Log
Management Describe:
“LogStash,Elastic & Kibana"
Present & Gathered by:
Reza Adineh
Cyber Security Specialist
SOC Expert
Forensic Researcher
Contact me: 

https://ir.linkedin.com/in/rezaadineh


Feb-2018
Module 1:Elastic: Product Portfolio
Phases : How to implement
Heart of ELK stack: Elasticsearch
Based on Apache Lucene
Shay Banon, Compass to Elasticsearch, released in 2010
In 2012 Elastic was founded in Amsterdam
RESTful search & Analytics engine
The Journey of an Event in elastic:
Plugin Ecosystem:
Rich Integration & Processing
200+ plugins
Extensible framework to easily build your own plugin
Logstash Plugins Maintainer Program
Module 2:What is ELK Stack ?
Need for log analysis
Lets understand why do we need log analysis ?
Needs for Log analysis
Problems with log analysis
Lets understand what problems occurred with log analysis ?
Log management tool
Lets now understand what exactly is ELK Stack.
Elastic Search
LogStash
Kibana
How exactly ELK Stack works ?
Many Companies use ELK Stack
Visualizing logs using ElasticSearch, Logstach & Kibana &
saving millions !
Keep a deeper look at Logs & how implement
ElasticSearch, Logstach & Kibana
Logs & Log structures:
A log is human readable …
A human readable, machine parsable representation of an
event.
Regex ?!
How to parse logs ?
OR Indexing & Labeling
Thinking open source :
Logstash
Graylog
Logalyse
Scribe
Hadooooop
Did you like it ?
Lets look at Logstash …
Logstash Architecture
Logstash Architecture :
Scaling Deployment:
Summary of Log’s Lifecycle:
Lets look at some
examples:
Define Some output:
Kibana custom dashboards :
Logstash- Twitter Input
Already have central Rsyslog/SyslogNg Server ?
Also you can use it as Central Syslog Server
It is too good for Appliances
Use matching input & outputs to Sendfile contents to
another log stash for processing.
Further reading on :
logstash.net
logstashbook.com
Juju charms.com/charms/precise/logstash-indexer
Logstash puppet module(github/electrical)
Any question ?
Contact me: 

https://ir.linkedin.com/in/
rezaadineh

Security monitoring log management-describe logstash,kibana,elastic slidshare