SlideShare a Scribd company logo
Security Event Monitoring,Log
Management Describe:
“LogStash,Elastic & Kibana"
Present & Gathered by:
Reza Adineh
Cyber Security Specialist
SOC Expert
Forensic Researcher
Contact me: 

https://ir.linkedin.com/in/rezaadineh


Feb-2018
Module 1:Elastic: Product Portfolio
Phases : How to implement
Security monitoring log management-describe logstash,kibana,elastic slidshare
Heart of ELK stack: Elasticsearch
Based on Apache Lucene
Shay Banon, Compass to Elasticsearch, released in 2010
In 2012 Elastic was founded in Amsterdam
RESTful search & Analytics engine
The Journey of an Event in elastic:
Security monitoring log management-describe logstash,kibana,elastic slidshare
Plugin Ecosystem:
Rich Integration & Processing
200+ plugins
Extensible framework to easily build your own plugin
Logstash Plugins Maintainer Program
Security monitoring log management-describe logstash,kibana,elastic slidshare
Module 2:What is ELK Stack ?
Security monitoring log management-describe logstash,kibana,elastic slidshare
Need for log analysis
Lets understand why do we need log analysis ?
Needs for Log analysis
Security monitoring log management-describe logstash,kibana,elastic slidshare
Security monitoring log management-describe logstash,kibana,elastic slidshare
Problems with log analysis
Lets understand what problems occurred with log analysis ?
Security monitoring log management-describe logstash,kibana,elastic slidshare
Security monitoring log management-describe logstash,kibana,elastic slidshare
Security monitoring log management-describe logstash,kibana,elastic slidshare
Security monitoring log management-describe logstash,kibana,elastic slidshare
Log management tool
Lets now understand what exactly is ELK Stack.
Elastic Search
Security monitoring log management-describe logstash,kibana,elastic slidshare
Security monitoring log management-describe logstash,kibana,elastic slidshare
Security monitoring log management-describe logstash,kibana,elastic slidshare
LogStash
Kibana
Security monitoring log management-describe logstash,kibana,elastic slidshare
How exactly ELK Stack works ?
Many Companies use ELK Stack
Visualizing logs using ElasticSearch, Logstach & Kibana &
saving millions !
Keep a deeper look at Logs & how implement
ElasticSearch, Logstach & Kibana
Logs & Log structures:
Security monitoring log management-describe logstash,kibana,elastic slidshare
A log is human readable …
A human readable, machine parsable representation of an
event.
Regex ?!
How to parse logs ?
OR Indexing & Labeling
Thinking open source :
Logstash
Graylog
Logalyse
Scribe
Hadooooop
Did you like it ?
Lets look at Logstash …
Logstash Architecture
Logstash Architecture :
Security monitoring log management-describe logstash,kibana,elastic slidshare
Scaling Deployment:
Summary of Log’s Lifecycle:
Lets look at some
examples:
Security monitoring log management-describe logstash,kibana,elastic slidshare
Security monitoring log management-describe logstash,kibana,elastic slidshare
Security monitoring log management-describe logstash,kibana,elastic slidshare
Define Some output:
Security monitoring log management-describe logstash,kibana,elastic slidshare
Kibana custom dashboards :
Logstash- Twitter Input
Security monitoring log management-describe logstash,kibana,elastic slidshare
Already have central Rsyslog/SyslogNg Server ?
Also you can use it as Central Syslog Server
It is too good for Appliances
Use matching input & outputs to Sendfile contents to
another log stash for processing.
Security monitoring log management-describe logstash,kibana,elastic slidshare
Security monitoring log management-describe logstash,kibana,elastic slidshare
Security monitoring log management-describe logstash,kibana,elastic slidshare
Security monitoring log management-describe logstash,kibana,elastic slidshare
Security monitoring log management-describe logstash,kibana,elastic slidshare
Further reading on :
logstash.net
logstashbook.com
Juju charms.com/charms/precise/logstash-indexer
Logstash puppet module(github/electrical)
Any question ?
Contact me: 

https://ir.linkedin.com/in/
rezaadineh

More Related Content

PPTX
Log analysis using Logstash,ElasticSearch and Kibana
PDF
Elasitcsearch + Logstash + Kibana 日誌監控
PPTX
Lessons Learned in Deploying the ELK Stack (Elasticsearch, Logstash, and Kibana)
PPTX
Log management with ELK
PDF
Search Analytics with ELK (Elastic Stack)
PDF
Log analysis with the elk stack
PPTX
PPTX
Using ELK-Stack (Elasticsearch, Logstash and Kibana) with BizTalk Server
Log analysis using Logstash,ElasticSearch and Kibana
Elasitcsearch + Logstash + Kibana 日誌監控
Lessons Learned in Deploying the ELK Stack (Elasticsearch, Logstash, and Kibana)
Log management with ELK
Search Analytics with ELK (Elastic Stack)
Log analysis with the elk stack
Using ELK-Stack (Elasticsearch, Logstash and Kibana) with BizTalk Server

What's hot (20)

PDF
ELK introduction
PDF
Logging with Elasticsearch, Logstash & Kibana
PDF
What's new in Elasticsearch v5
PDF
Log analytics with ELK stack
PDF
Metrics, Logs, Transaction Traces, Anomaly Detection at Scale
PDF
Elasticsearch in Netflix
PPTX
Microservices, Continuous Delivery, and Elasticsearch at Capital One
PDF
ELK: a log management framework
PPTX
ELK Elasticsearch Logstash and Kibana Stack for Log Management
PDF
Elasticsearch JVM-MX Meetup April 2016
PDF
How to win skeptics to aggregated logging using Vagrant and ELK
PPTX
Nagios Conference 2014 - Scott Wilkerson - Log Monitoring and Log Management ...
PPTX
The ultimate guide for Elasticsearch plugins
PDF
Using Elastic to Monitor Everything - Christoph Wurm, Elastic - DevOpsDays Te...
PDF
Practical Elasticsearch - real world use cases
PPTX
NATE-Central-Log
PPTX
Monitoring as Code - Ignite
PPTX
Icinga Camp Bangalore - Icinga2 API use cases and BlueJeans Inc.
PDF
Apache Pulsar Community-Jennifer
PDF
DOD 2016 - Rafał Kuć - Building a Resilient Log Aggregation Pipeline Using El...
ELK introduction
Logging with Elasticsearch, Logstash & Kibana
What's new in Elasticsearch v5
Log analytics with ELK stack
Metrics, Logs, Transaction Traces, Anomaly Detection at Scale
Elasticsearch in Netflix
Microservices, Continuous Delivery, and Elasticsearch at Capital One
ELK: a log management framework
ELK Elasticsearch Logstash and Kibana Stack for Log Management
Elasticsearch JVM-MX Meetup April 2016
How to win skeptics to aggregated logging using Vagrant and ELK
Nagios Conference 2014 - Scott Wilkerson - Log Monitoring and Log Management ...
The ultimate guide for Elasticsearch plugins
Using Elastic to Monitor Everything - Christoph Wurm, Elastic - DevOpsDays Te...
Practical Elasticsearch - real world use cases
NATE-Central-Log
Monitoring as Code - Ignite
Icinga Camp Bangalore - Icinga2 API use cases and BlueJeans Inc.
Apache Pulsar Community-Jennifer
DOD 2016 - Rafał Kuć - Building a Resilient Log Aggregation Pipeline Using El...
Ad

Similar to Security monitoring log management-describe logstash,kibana,elastic slidshare (20)

PPTX
ELK Ruminating on Logs (Zendcon 2016)
PPTX
Log analysis using Logstash,ElasticSearch and Kibana - Desert Code Camp 2014
PPTX
ELK Stack
DOCX
Log management with_logstash_and_elastic_search
PDF
2015 03-16-elk at-bsides
PDF
elkstack-161217091231.pdf
PPTX
Elk ruminating on logs
PPTX
Kibana+ElasticSearch+LogStash to handle Log messages on Prod servers
PPTX
Centralized Logging System Using ELK Stack
PDF
Présentation ELK/SIEM et démo Wazuh
PDF
What Is ELK Stack | ELK Tutorial For Beginners | Elasticsearch Kibana | ELK S...
PPTX
PowerPoint Presentation Guide Cyber.pptx
PDF
Technology behind-real-time-log-analytics
PPTX
ELK Stack Online Training - ELK Stack Training.pptx
PPTX
438996599-Kibana-101-pptx.pptx
PDF
"How about no grep and zabbix?". ELK based alerts and metrics.
PDF
Logs aggregation and analysis
PPTX
Logs management
PPTX
The Elastic Stack as a SIEM
PDF
2.ELK.pdf
ELK Ruminating on Logs (Zendcon 2016)
Log analysis using Logstash,ElasticSearch and Kibana - Desert Code Camp 2014
ELK Stack
Log management with_logstash_and_elastic_search
2015 03-16-elk at-bsides
elkstack-161217091231.pdf
Elk ruminating on logs
Kibana+ElasticSearch+LogStash to handle Log messages on Prod servers
Centralized Logging System Using ELK Stack
Présentation ELK/SIEM et démo Wazuh
What Is ELK Stack | ELK Tutorial For Beginners | Elasticsearch Kibana | ELK S...
PowerPoint Presentation Guide Cyber.pptx
Technology behind-real-time-log-analytics
ELK Stack Online Training - ELK Stack Training.pptx
438996599-Kibana-101-pptx.pptx
"How about no grep and zabbix?". ELK based alerts and metrics.
Logs aggregation and analysis
Logs management
The Elastic Stack as a SIEM
2.ELK.pdf
Ad

More from ReZa AdineH (16)

PPTX
The Evolution of SIEM- From Logs to Detection-First Intelligence.pptx
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PPTX
From Zero to SOC: Designing Effective Threat Detection & Incident Response
PDF
MITRE-Module 1 Slides.pdf
PDF
MITRE-Module 2 Slides.pdf
PDF
MITRE-Module 4 Slides.pdf
PDF
MITRE-Module 5 Slides.pdf
PDF
MITRE-Module 3 Slides.pdf
PDF
SIEM POC Assessment.pdf
PDF
Cover of book Threat Intelligence for Threat Hunting;Written by Reza Adineh
PDF
Next generation Security Operation Center; Written by Reza Adineh
PPTX
Review on Event Correlation- مروری بر روش های همبسته سازی در مدیریت رخداد
PPTX
Effective Security Operation Center - present by Reza Adineh
PDF
علت ناکامی بسیاری از پروژههای مرکزعملیاتامنیت چیست ؟
PDF
Security operations center-SOC Presentation-مرکز عملیات امنیت
The Evolution of SIEM- From Logs to Detection-First Intelligence.pptx
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
From Zero to SOC: Designing Effective Threat Detection & Incident Response
MITRE-Module 1 Slides.pdf
MITRE-Module 2 Slides.pdf
MITRE-Module 4 Slides.pdf
MITRE-Module 5 Slides.pdf
MITRE-Module 3 Slides.pdf
SIEM POC Assessment.pdf
Cover of book Threat Intelligence for Threat Hunting;Written by Reza Adineh
Next generation Security Operation Center; Written by Reza Adineh
Review on Event Correlation- مروری بر روش های همبسته سازی در مدیریت رخداد
Effective Security Operation Center - present by Reza Adineh
علت ناکامی بسیاری از پروژههای مرکزعملیاتامنیت چیست ؟
Security operations center-SOC Presentation-مرکز عملیات امنیت

Recently uploaded (20)

PDF
Mega Projects Data Mega Projects Data
PDF
annual-report-2024-2025 original latest.
PDF
Foundation of Data Science unit number two notes
PPTX
01_intro xxxxxxxxxxfffffffffffaaaaaaaaaaafg
PDF
Fluorescence-microscope_Botany_detailed content
PDF
168300704-gasification-ppt.pdfhghhhsjsjhsuxush
PDF
Lecture1 pattern recognition............
PPTX
Introduction to machine learning and Linear Models
PPTX
Database Infoormation System (DBIS).pptx
PPTX
1_Introduction to advance data techniques.pptx
PPTX
iec ppt-1 pptx icmr ppt on rehabilitation.pptx
PPTX
Acceptance and paychological effects of mandatory extra coach I classes.pptx
PDF
BF and FI - Blockchain, fintech and Financial Innovation Lesson 2.pdf
PPTX
climate analysis of Dhaka ,Banglades.pptx
PDF
Business Analytics and business intelligence.pdf
PPTX
Computer network topology notes for revision
PPTX
Microsoft-Fabric-Unifying-Analytics-for-the-Modern-Enterprise Solution.pptx
PPTX
AI Strategy room jwfjksfksfjsjsjsjsjfsjfsj
PPTX
Business Acumen Training GuidePresentation.pptx
PDF
22.Patil - Early prediction of Alzheimer’s disease using convolutional neural...
Mega Projects Data Mega Projects Data
annual-report-2024-2025 original latest.
Foundation of Data Science unit number two notes
01_intro xxxxxxxxxxfffffffffffaaaaaaaaaaafg
Fluorescence-microscope_Botany_detailed content
168300704-gasification-ppt.pdfhghhhsjsjhsuxush
Lecture1 pattern recognition............
Introduction to machine learning and Linear Models
Database Infoormation System (DBIS).pptx
1_Introduction to advance data techniques.pptx
iec ppt-1 pptx icmr ppt on rehabilitation.pptx
Acceptance and paychological effects of mandatory extra coach I classes.pptx
BF and FI - Blockchain, fintech and Financial Innovation Lesson 2.pdf
climate analysis of Dhaka ,Banglades.pptx
Business Analytics and business intelligence.pdf
Computer network topology notes for revision
Microsoft-Fabric-Unifying-Analytics-for-the-Modern-Enterprise Solution.pptx
AI Strategy room jwfjksfksfjsjsjsjsjfsjfsj
Business Acumen Training GuidePresentation.pptx
22.Patil - Early prediction of Alzheimer’s disease using convolutional neural...

Security monitoring log management-describe logstash,kibana,elastic slidshare