* Update ELK to version 5.4.2

* Update Wazuh Kibana Plugin to version 2.0_5.4.2
This commit is contained in:
Jose Luis Ruiz
2017-06-21 12:15:48 +02:00
parent 754915cb35
commit e6e30ab3aa
6 changed files with 10 additions and 9 deletions
+1 -1
View File
@@ -2,7 +2,7 @@
The first time than you runt this container can take a while until kibana finish the configuration, the Wazuh plugin can take a few minutes until finish the instalation, please be patient. The first time than you runt this container can take a while until kibana finish the configuration, the Wazuh plugin can take a few minutes until finish the instalation, please be patient.
# Docker container Wazuh + ELK(5.3.0) # Docker container Wazuh 2.0 + ELK(5.4.2)
This Docker container source files can be found in our [Wazuh Github repository](https://github.com/wazuh/wazuh). It includes both an OSSEC manager and an Elasticsearch single-node cluster, with Logstash and Kibana. You can find more information on how these components work together in our documentation. This Docker container source files can be found in our [Wazuh Github repository](https://github.com/wazuh/wazuh). It includes both an OSSEC manager and an Elasticsearch single-node cluster, with Logstash and Kibana. You can find more information on how these components work together in our documentation.
+1 -1
View File
@@ -36,7 +36,7 @@ services:
environment: environment:
- LS_HEAP_SIZE=2048m - LS_HEAP_SIZE=2048m
elasticsearch: elasticsearch:
image: elasticsearch:5.3.0 image: elasticsearch:5.4.2
hostname: elasticsearch hostname: elasticsearch
restart: always restart: always
command: elasticsearch -E node.name="node-1" -E cluster.name="wazuh" -E network.host=0.0.0.0 command: elasticsearch -E node.name="node-1" -E cluster.name="wazuh" -E network.host=0.0.0.0
+1 -1
View File
@@ -1,4 +1,4 @@
FROM kibana:5.3.0 FROM kibana:5.4.2
RUN apt-get update && apt-get install -y curl RUN apt-get update && apt-get install -y curl
+1 -1
View File
@@ -1,4 +1,4 @@
FROM logstash:5.3.0 FROM logstash:5.4.2
RUN apt-get update RUN apt-get update
+4 -3
View File
@@ -13,7 +13,7 @@ input {
#input { #input {
# file { # file {
# type => "wazuh-alerts" # type => "wazuh-alerts"
# path => "/var/ossec/data/logs/alerts/alerts.json" # path => "/var/ossec/logs/alerts/alerts.json"
# codec => "json" # codec => "json"
# } # }
#} #}
@@ -21,18 +21,19 @@ filter {
geoip { geoip {
source => "srcip" source => "srcip"
target => "GeoLocation" target => "GeoLocation"
fields => ["city_name", "continent_code", "country_code2", "country_name", "region_name", "location"]
} }
date { date {
match => ["timestamp", "ISO8601"] match => ["timestamp", "ISO8601"]
target => "@timestamp" target => "@timestamp"
} }
mutate { mutate {
remove_field => [ "timestamp", "beat", "fields", "input_type", "tags", "count" ] remove_field => [ "timestamp", "beat", "fields", "input_type", "tags", "count", "@version", "log", "offset", "type"]
} }
} }
output { output {
elasticsearch { elasticsearch {
hosts => ["elasticsearch:9200"] hosts => ["localhost:9200"]
index => "wazuh-alerts-%{+YYYY.MM.dd}" index => "wazuh-alerts-%{+YYYY.MM.dd}"
document_type => "wazuh" document_type => "wazuh"
template => "/etc/logstash/wazuh-elastic5-template.json" template => "/etc/logstash/wazuh-elastic5-template.json"
+2 -2
View File
@@ -18,8 +18,8 @@ RUN chmod 755 /init.bash &&\
sync && rm /init.bash sync && rm /init.bash
RUN curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-5.1.2-x86_64.rpm &&\ RUN curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-5.4.2-x86_64.rpm &&\
rpm -vi filebeat-5.1.2-x86_64.rpm && rm filebeat-5.1.2-x86_64.rpm rpm -vi filebeat-5.4.2-x86_64.rpm && rm filebeat-5.4.2-x86_64.rpm
COPY config/filebeat.yml /etc/filebeat/ COPY config/filebeat.yml /etc/filebeat/