Guest User

Untitled

a guest
Mar 8th, 2020
424
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.12 KB | None | 0 0
  1. wget https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-7.6.1-amd64.deb
  2. wget https://artifacts.elastic.co/downloads/logstash/logstash-7.6.1.deb
  3. wget https://artifacts.elastic.co/downloads/kibana/kibana-7.6.1-amd64.deb
  4.  
  5. =======ELASTICSEARCH=======================
  6. dpkg -i elasticsearch-7.6.1-amd64.deb
  7. service elasticsearch status
  8. service elasticsearch start
  9.  
  10. tail -f /var/log/elasticsearch/elasticsearch.log
  11. curl -XGET localhost:9200
  12. lsof -i:9200
  13. ===========================================
  14.  
  15. =======LOGSTASH============================
  16. dpkg -i logstash-7.6.1.deb
  17. service logstash status
  18. cd /etc/logstash/conf.d/
  19. wget (ip)/01_inputs.conf
  20. wget (ip)/02_windows.conf
  21. wget (ip)/99_outputs.conf
  22. ########creamos comando de test
  23. echo "/usr/share/logstash/bin/logstash --config.test_and_exit -f /etc/logstash/conf.d/" > /etc/logstash/test.sh
  24. chmod +x /etc/logstash/test.sh
  25. ./test.sh
  26. ###############################
  27. SI NOS SALE "Config Validation Result: OK. Exiting Logstash" SEGUIMOS:
  28. service logstash start
  29. tail -f /var/log/logstash/logstash-plain.log
  30. PARA CONTINUAR EN LOS LOGS TENEMOS QUE LEER ESTO "Successfully started Logstash API endpoint {:port=>9600}"
  31. lsof -i:5044dpkg -i kibana-7.6.1-amd64.deb
  32. ===========================================
  33. =======KIBANA==============================
  34. dpkg -i kibana-7.6.1-amd64.deb
  35. echo 'server.host: "0.0.0.0"' >> /etc/kibana/kibana.yml
  36. service kibana start
  37. service kibana status
  38. lsof -i:5601
  39. http://IP:5601
  40. ===========================================
  41. =======WINLOGBEAT==========================
  42. https://www.elastic.co/es/downloads/beats/winlogbeat
  43. https://artifacts.elastic.co/downloads/beats/winlogbeat/winlogbeat-7.6.1-windows-x86_64.msi
  44. admin cmd:
  45. cd C:\ProgramData\Elastic\Beats\winlogbeat
  46. notepad winlogbeat.yml
  47.  
  48. PEGAMOS DE LLAVES (sin las llaves claro)
  49. {
  50. winlogbeat.event_logs:
  51. - name: Security
  52.  
  53. output.logstash:
  54. hosts:
  55. - IP:5044
  56.  
  57. logging.to_files: true
  58. logging.files:
  59. path: C:\ProgramData\winlogbeat\Logs
  60. logging.level: info
  61. }
  62. services.msc -> iniciar "Elastic Winlogbeat 7.6.1"
  63. ===========================================
Advertisement
Add Comment
Please, Sign In to add comment