stamusnetworks / kts5 Goto Github PK
View Code? Open in Web Editor NEWKibana 5 Templates for Suricata IDPS
License: GNU General Public License v3.0
Kibana 5 Templates for Suricata IDPS
License: GNU General Public License v3.0
Hi,
Due to the spaces in the name of the dashboards, they cannot be found in the most recent version of kibana (i believe its 5.5)
Additionally, it would be really awesome if the index names could be adjusted easily ;)
Thanks!
Issue in "SN Alerts" dashboard.
the smtp.helo.raw isn't created by default, hence an error occurs.
Hello,
Using these great dashboards on a RedHat EL 7.4 server and after updating via the yum repo from 5.5 to 5.6.0.1, Kibana is in a RED status:
[illegal_argument_exception] mapper [hits] cannot be changed from type [long] to [integer]
So I stopped kibana, removed the kibana index, loaded the dasboards again and started kibana but to no avail:
$ systemctl stop kibana
$ curl -XDELETE http://localhost:9200/.kibana
$ find KTS5/dashboards/ -type f -exec sed -i -e 's/.raw/.keyword/g' {} ;
$ ./load.sh
$ systemctl start kibana
Any idea how to solve this?
Much appreciated!
Andre
Hello,
Migrating elasticsearch from 5.6 to 6 did not show major problems regarding already collected data via the SELKS setup on RedHat EL 7, but Kibana 6 fails. Are you planning a release of KTS5 (or maybe KTS6) which will work on ELK 6?
Kind regards,
Andre
After stopping Kibana, removing the index .Kibana and starting Kibana, it works well. But after running the load.sh script it reports import errors and Kibana itself afterwards reports " Your Kibana index is out of date, reset it or use the X-Pack upgrade assistant. "
Loading dashboard SN-STATS:
WIth the latest version of kibana and using the KTS5 dashboards I am getting:
No results found on a lot of visualizations.
When I the field list they change to:
Could not locate that index-pattern-field (id: ...).
I fixed this issue by changing the .raw entries to .keyword in the visualizations.
This seems to have changed with ELK 5: https://www.elastic.co/guide/en/logstash/current/breaking-changes.html#_elasticsearch_output_index_template
Received the following in Kibana. Thoughts on how to fix?
Error: unknown error
ErrorAbstract@http://192.168.3.249:5601/bundles/kibana.bundle.js?v=15616:12:24939
errors.Generic@http://192.168.3.249:5601/bundles/kibana.bundle.js?v=15616:12:25973
respond@http://192.168.3.249:5601/bundles/kibana.bundle.js?v=15616:13:2793
checkRespForFailure@http://192.168.3.249:5601/bundles/kibana.bundle.js?v=15616:13:1959
AngularConnector.prototype.request/<@http://192.168.3.249:5601/bundles/kibana.bundle.js?v=15616:2:341
processQueue@http://192.168.3.249:5601/bundles/commons.bundle.js?v=15616:38:23621
scheduleProcessQueue/<@http://192.168.3.249:5601/bundles/commons.bundle.js?v=15616:38:23888
$eval@http://192.168.3.249:5601/bundles/commons.bundle.js?v=15616:39:4607
$digest@http://192.168.3.249:5601/bundles/commons.bundle.js?v=15616:39:2343
$apply@http://192.168.3.249:5601/bundles/commons.bundle.js?v=15616:39:5026
done@http://192.168.3.249:5601/bundles/commons.bundle.js?v=15616:37:25016
completeRequest@http://192.168.3.249:5601/bundles/commons.bundle.js?v=15616:37:28702
requestError@http://192.168.3.249:5601/bundles/commons.bundle.js?v=15616:37:29744
Hello,
I'm newbie on ELK but I dont have clear how I can transmit suricata logs to elasticsearch.
Do you use logstash? any other way?
Thank you
Hello,
I have just installed ELK 5.5.1 and try to import KTS5.
After running ./load.sh and login to Kibana I got message with patten "logstash-*"
Mapping conflict
A field is defined as several types (string, integer, etc) across the indices that match this pattern. You may still be able to use these conflict fields in parts of Kibana, but they will be unavailable for functions that require Kibana to know their type. Correcting this issue will require reindexing your data.
The conflict filed is geoip.coordinates
The type of this field changes across indices. It is unavailable for many analysis functions. The indices per type are as follows:
Type | Index Names |
---|---|
float | logstash-alert-2016.08.12-reindexed, logstash-alert-2017.07.05, logstash-alert-2017.07.12, logstash-alert-2017.07.12-reindexed, logstash-alert-2017.07.13, logstash-dns-2017.07.05, logstash-fileinfo-2016.08.12-reindexed, logstash-fileinfo-2017.07.05, logstash-fileinfo-2017.07.12, logstash-fileinfo-2017.07.12-reindexed, logstash-fileinfo-2017.07.13, logstash-flow-2017.07.05, logstash-flow-2017.07.12, logstash-flow-2017.07.12-reindexed, logstash-flow-2017.07.13, logstash-http-2017.07.05, logstash-http-2017.07.12, logstash-http-2017.07.12-reindexed, logstash-http-2017.07.13, logstash-smtp-2017.07.05, logstash-ssh-2017.07.05, logstash-tls-2017.07.05, logstash-tls-2017.07.12, logstash-tls-2017.07.12-reindexed, logstash-tls-2017.07.13 |
long | logstash-flow-2016.08.12-reindexed, logstash-http-2016.08.12-reindexed, logstash-tls-2016.08.12-reindexed |
Could you please tell me how to fix this issue?
Thank you!
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.