Elastic Lab (part 7) - Conclusion and Shortcuts
Elastic Logo

Elastic Lab (part 7) - Conclusion and Shortcuts

Concluding this project, here are the parts (mostly for my ease of access):

Part Zero - Introduction

Part 1 - Installing VMWare

Part 2 - Installing Debian Linux

Part 3 - Installing Elastic

Part 4 - Installing and configuring Kibana

Part 5 - Installing Logstash

Part 6 - Installing Winlogbeat

Several great people have pointed out that there are easier ways to do this.

YES THERE ARE. The above lab is to learn different skills, see how some of the ELK stack components work together, and what they need. It is NOT a professional buildout (missing certificates, encryption, authentication and authorization, just to start). It's for someone building a SIEM as a START to a cybersecurity journey.

Now, if someone wants to skip part of that headache, it's totally possible to grab the work someone else has done. Containers have been built which have the ELK stack already ready to go without so much work.

Here's one in Github

And Here's another in Github.

In addition, if you go to the Docker Hub and search for "elastic" you will find LOTS of containers that are ready to go. I HIGHLY recommend you check it out!

"WHY OH WHY" did I not just post these links from the beginning?

I think learning is a process, and anyone who has put their own ELK stack together from scratch has probably learned quite a bit. When I was introduced to firewalls in 2010, we built access control rules from scratch piece by piece to understand what the stateful firewall was doing- a very frustrating exercise that was very informative.

Hope you've had fun! But more importantly learned something, and have some tools to utilize. Please let me know if there's anything I can improve in these articles. :)

Stephen G.

Neurodiverse Leader, Soldier, & MBA & MSIS Student | Passionate About Developing People and Achieving Win/Win Outcomes

1 个月

Great job William! There are always easier or better ways to do something - but you were trying to learn and learning requires mistakes. Keep learning and keep sharing!

要查看或添加评论,请登录

William Douglass的更多文章

  • Elastic Lab (part 6) - Winlogbeat

    Elastic Lab (part 6) - Winlogbeat

    This project left off with getting Logstash running. This has been an exercise in refreshing some Linux, VMWare, and…

  • Elastic Lab (part 5) - Logstash

    Elastic Lab (part 5) - Logstash

    WHEW. That's been a lot of work.

  • Elastic Lab (part 4) - Kibana

    Elastic Lab (part 4) - Kibana

    Part 3 of this fun exercise finished with installing Elasticsearch. However Elastic is only one piece of the puzzle…

  • Elastic Lab (part 3) - Install Elastic

    Elastic Lab (part 3) - Install Elastic

    In Part 2 of this project, you've installed Debian as the Operating System on a Virtual Machine in VMWare Workstation…

  • Elastic Lab (part 2) - Install Debian Linux

    Elastic Lab (part 2) - Install Debian Linux

    In part 1 I dropped the link and how to install VMWare and configure the network. I would recommend reading through all…

  • Elastic Lab (part 1) - Install VMWare Workstation Pro

    Elastic Lab (part 1) - Install VMWare Workstation Pro

    In part zero I explained a little about what this project is all about. Now it's time to build the infrastructure.

  • Elastic Lab (part 0) - About this project

    Elastic Lab (part 0) - About this project

    While I'm waiting for access to start my "real work" as a Cyber Analyst, I dug into building a lab to play around with.…

    5 条评论

社区洞察

其他会员也浏览了