mirror of https://github.com/infosecn1nja/HELK.git
Updating pipeline
+ added new topic to replace winlogbeat in future updates + updated nxlog mordor to test raw eventsneu5ron-patch-1
parent
060fdf7a2a
commit
c6c272c2e6
|
@ -135,7 +135,7 @@ services:
|
|||
REPLICATION_FACTOR: 1
|
||||
ADVERTISED_LISTENER: ${ADVERTISED_LISTENER}
|
||||
ZOOKEEPER_NAME: helk-zookeeper
|
||||
KAFKA_CREATE_TOPICS: winlogbeat, SYSMON_JOIN, filebeat, mordor
|
||||
KAFKA_CREATE_TOPICS: winlogbeat, winevent, SYSMON_JOIN, filebeat
|
||||
KAFKA_HEAP_OPTS: -Xmx1G -Xms1G
|
||||
LOG_RETENTION_HOURS: 4
|
||||
ports:
|
||||
|
|
|
@ -138,7 +138,7 @@ services:
|
|||
REPLICATION_FACTOR: 1
|
||||
ADVERTISED_LISTENER: ${ADVERTISED_LISTENER}
|
||||
ZOOKEEPER_NAME: helk-zookeeper
|
||||
KAFKA_CREATE_TOPICS: winlogbeat, SYSMON_JOIN, filebeat, mordor
|
||||
KAFKA_CREATE_TOPICS: winlogbeat, winevent, SYSMON_JOIN, filebeat
|
||||
KAFKA_HEAP_OPTS: -Xmx1G -Xms1G
|
||||
LOG_RETENTION_HOURS: 4
|
||||
ports:
|
||||
|
|
|
@ -110,7 +110,7 @@ services:
|
|||
REPLICATION_FACTOR: 1
|
||||
ADVERTISED_LISTENER: ${ADVERTISED_LISTENER}
|
||||
ZOOKEEPER_NAME: helk-zookeeper
|
||||
KAFKA_CREATE_TOPICS: winlogbeat, SYSMON_JOIN, filebeat, mordor
|
||||
KAFKA_CREATE_TOPICS: winlogbeat, winevent, SYSMON_JOIN, filebeat
|
||||
KAFKA_HEAP_OPTS: -Xmx1G -Xms1G
|
||||
LOG_RETENTION_HOURS: 4
|
||||
ports:
|
||||
|
|
|
@ -138,7 +138,7 @@ services:
|
|||
REPLICATION_FACTOR: 1
|
||||
ADVERTISED_LISTENER: ${ADVERTISED_LISTENER}
|
||||
ZOOKEEPER_NAME: helk-zookeeper
|
||||
KAFKA_CREATE_TOPICS: winlogbeat, SYSMON_JOIN, filebeat, mordor
|
||||
KAFKA_CREATE_TOPICS: winlogbeat, winevent, SYSMON_JOIN, filebeat
|
||||
KAFKA_HEAP_OPTS: -Xmx1G -Xms1G
|
||||
LOG_RETENTION_HOURS: 4
|
||||
ports:
|
||||
|
|
|
@ -135,7 +135,7 @@ services:
|
|||
REPLICATION_FACTOR: 1
|
||||
ADVERTISED_LISTENER: ${ADVERTISED_LISTENER}
|
||||
ZOOKEEPER_NAME: helk-zookeeper
|
||||
KAFKA_CREATE_TOPICS: winlogbeat, SYSMON_JOIN, filebeat, mordor
|
||||
KAFKA_CREATE_TOPICS: winlogbeat, winevent, SYSMON_JOIN, filebeat
|
||||
KAFKA_HEAP_OPTS: -Xmx1G -Xms1G
|
||||
LOG_RETENTION_HOURS: 4
|
||||
ports:
|
||||
|
|
|
@ -139,7 +139,7 @@ services:
|
|||
REPLICATION_FACTOR: 1
|
||||
ADVERTISED_LISTENER: ${ADVERTISED_LISTENER}
|
||||
ZOOKEEPER_NAME: helk-zookeeper
|
||||
KAFKA_CREATE_TOPICS: winlogbeat, SYSMON_JOIN, filebeat, mordor
|
||||
KAFKA_CREATE_TOPICS: winlogbeat, winevent, SYSMON_JOIN, filebeat
|
||||
KAFKA_HEAP_OPTS: -Xmx1g -Xms1g
|
||||
LOG_RETENTION_HOURS: 4
|
||||
ports:
|
||||
|
|
|
@ -135,7 +135,7 @@ services:
|
|||
REPLICATION_FACTOR: 1
|
||||
ADVERTISED_LISTENER: ${ADVERTISED_LISTENER}
|
||||
ZOOKEEPER_NAME: helk-zookeeper
|
||||
KAFKA_CREATE_TOPICS: winlogbeat, SYSMON_JOIN, filebeat, mordor
|
||||
KAFKA_CREATE_TOPICS: winlogbeat, winevent, SYSMON_JOIN, filebeat
|
||||
KAFKA_HEAP_OPTS: -Xmx1G -Xms1G
|
||||
LOG_RETENTION_HOURS: 4
|
||||
ports:
|
||||
|
|
|
@ -139,7 +139,7 @@ services:
|
|||
REPLICATION_FACTOR: 1
|
||||
ADVERTISED_LISTENER: ${ADVERTISED_LISTENER}
|
||||
ZOOKEEPER_NAME: helk-zookeeper
|
||||
KAFKA_CREATE_TOPICS: winlogbeat, SYSMON_JOIN, filebeat, mordor
|
||||
KAFKA_CREATE_TOPICS: winlogbeat, winevent, SYSMON_JOIN, filebeat
|
||||
KAFKA_HEAP_OPTS: -Xmx1g -Xms1g
|
||||
LOG_RETENTION_HOURS: 4
|
||||
ports:
|
||||
|
|
|
@ -6,7 +6,5 @@
|
|||
input {
|
||||
tcp {
|
||||
port => 3515
|
||||
type => "nxlog-mordor"
|
||||
#codec => json { charset => "CP1252" }
|
||||
}
|
||||
}
|
|
@ -4,12 +4,10 @@
|
|||
# License: GPL-3.0
|
||||
|
||||
filter {
|
||||
if [type] == "nxlog-mordor" {
|
||||
json {
|
||||
source => "message"
|
||||
tag_on_failure => [ "_jsonparsefailure", "_parsefailure", "_jsonparsefailure_0301" ]
|
||||
remove_field => [ "message" ]
|
||||
add_field => { "z_logstash_pipeline" => "json-0003-001" }
|
||||
}
|
||||
json {
|
||||
source => "message"
|
||||
tag_on_failure => [ "_jsonparsefailure", "_parsefailure", "_jsonparsefailure_0301" ]
|
||||
remove_field => [ "Message" ]
|
||||
add_tag => [ "mordorDataset" ]
|
||||
}
|
||||
}
|
|
@ -4,11 +4,9 @@
|
|||
# License: GPL-3.0
|
||||
|
||||
output {
|
||||
if [type] == "nxlog-mordor" {
|
||||
kafka {
|
||||
bootstrap_servers => "helk-kafka-broker:9092"
|
||||
codec => "json"
|
||||
topic_id => "mordor"
|
||||
}
|
||||
}
|
||||
kafka {
|
||||
bootstrap_servers => "helk-kafka-broker:9092"
|
||||
codec => "json"
|
||||
topic_id => "winevent"
|
||||
}
|
||||
}
|
|
@ -6,7 +6,7 @@
|
|||
input {
|
||||
kafka {
|
||||
bootstrap_servers => "helk-kafka-broker:9092"
|
||||
topics => ["winlogbeat", "SYSMON_JOIN","filebeat"]
|
||||
topics => ["winlogbeat","winevent","SYSMON_JOIN","filebeat"]
|
||||
decorate_events => true
|
||||
codec => "json"
|
||||
auto_offset_reset => "latest"
|
||||
|
|
Loading…
Reference in New Issue