Differences between revisions 11 and 12
Revision 11 as of 2021-04-11 21:23:41
Size: 1078
Editor: scot
Comment:
Revision 12 as of 2021-04-11 21:35:29
Size: 1395
Editor: scot
Comment:
Deletions are marked like this. Additions are marked like this.
Line 9: Line 9:
 * Elk Stack (here is a good tutorial by [[https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elastic-stack-on-ubuntu-18-04|digitialocean.com]]
 * !GreyLog
Line 10: Line 12:
 * !GreyLog
 * Splunk (Seems to have gone for pay... probably want to try something else)
 * Splunk (Seems to have gone for pay... probably want to try something else. Never-the-less one of the top rated apps!)

/* Not log analyzers that do similar things

 * PRTG (billed as a network monitor similar to spiceworks, so it does more than
Line 13: Line 18:
 * !AlienVault (community edition)
 * Elk Stack
 * SolarWInds Paper Trail (trial version 48 hours of search 7 days of archive)
 * !AlienVault (community edition Threat intelligence, now owned by AT&T)
*/

Lab 09 Dashboards - Keeping data under control

Introduction

In the last two labs particularly, we have gathered information. But how do you make sense of it all? Log analyzer and dashboards!

Take the first 15 minutes of lab to research dashboards that you might want to install and use to work with Suricata, OpenVas and your windows systems.

  • Elk Stack (here is a good tutorial by digitialocean.com

  • GreyLog

  • Logz.io
  • Splunk (Seems to have gone for pay... probably want to try something else. Never-the-less one of the top rated apps!)

  • PRTG (billed as a network monitor similar to spiceworks, so it does more than
  • Spiceworks (and other variants)
  • AlienVault (community edition Threat intelligence, now owned by AT&T)

*/

Install a system of your choice. If its not on the list, check with me first and if its ok, I'll add it. You should collect information from OpenVas, Suricata, Windows Logs and ubuntu for aggregation in the dashboard of your choice.

Show Me

In less than two minutes:

  1. Show your Dashboard working
    1. Show something from OpenVas

    2. Show something from Suricata
    3. Show something from your Windows Server

NetworkSecurity/Lab/Lab09 (last edited 2021-04-11 22:20:51 by scot)