Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense + Elasticsearch, Logstash, Kibana (ELK) stack

    Scheduled Pinned Locked Moved Russian
    12 Posts 3 Posters 8.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pigbrother
      last edited by

      Наткнулся на эту тему с месяц назад. Тема, конечно, интересная.
      Однако времени потребует изрядно. Даже просто приложенный вами набор ссылок тянет на небольшой мануал…

      1 Reply Last reply Reply Quote 0
      • P
        pigbrother
        last edited by

        С реддита
        https://www.reddit.com/r/PFSENSE/comments/4dymci/i_made_a_simple_bare_bones_simple_elk_vm_for/

        I made a simple bare bones simple ELK VM for download. For fellow ELK N00bs
        I have put it on dropbox here: https://www.dropbox.com/s/aqd44gjrx7ghmm6/PFELK01-160408.ova?dl=0

        It's a VMWare OVA file.

        Basic setup based on http://pfelk.3ilson.com/ (bit on youtube at end to fix kibana)
        no SSL access
        DHCP
        Basic examples of different visualisations and dashboard configured
        Curator installed but no cron (https://www.elastic.co/guide/en/elasticsearch/client/curator/current/examples.html)

        Username: pf Password: pf
        Interface Port: http://ipaddress:5601
        Send firewall events to port 5140

        Changes you MUST make:
        sudo nano /etc/hosts (Change IP address and / or host)
        sudo nano /etc/logstash/conf.d/10-syslog.confcd (Change the IP on line 4 to be your PFsense box)

        1 Reply Last reply Reply Quote 0
        • werterW
          werter
          last edited by

          This post is deleted!
          1 Reply Last reply Reply Quote 0
          • H
            hamed_forum
            last edited by

            Please produced any VM for elk

            1 Reply Last reply Reply Quote 0
            • P
              pigbrother
              last edited by

              ELK + pfSense 2.3 Working
              https://forum.pfsense.org/index.php?topic=120937.0

              1 Reply Last reply Reply Quote 0
              • werterW
                werter
                last edited by

                This post is deleted!
                1 Reply Last reply Reply Quote 0
                • P
                  pigbrother
                  last edited by

                  Тема продолжается:
                  ELK Stack with Ubuntu 16.04 running and collecting pfSense logs!
                  https://www.reddit.com/r/PFSENSE/comments/702uam/elk_stack_with_ubuntu_1604_running_and_collecting/

                  1 Reply Last reply Reply Quote 0
                  • werterW
                    werter
                    last edited by

                    This post is deleted!
                    1 Reply Last reply Reply Quote 0
                    • werterW
                      werter
                      last edited by

                      This post is deleted!
                      1 Reply Last reply Reply Quote 0
                      • werterW
                        werter
                        last edited by

                        This post is deleted!
                        1 Reply Last reply Reply Quote 0
                        • werterW
                          werter
                          last edited by werter

                          Добрый.
                          Подчистил и обновил ссылки.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.