===step after dashboard done =>
https://docs.securityonion.net/en/2.3/logstash.htmlถ้าเจอว่า master node ไม่สามารถค้นหาได้ และเกิด error
"Error: Could not locate that index-pattern-field (id: @timestamp)"
# ls -la /opt/so/conf/logstash/pipelines/manager
total 20
drwxr-xr-x 2 logstash socore 4096 May 22 23:57 .
drwxr-xr-x 4 logstash socore 4096 May 29 23:42 ..
-rw-r--r-- 1 logstash socore 69 May 22 23:57 0009_input_beats.conf
-rw-r--r-- 1 logstash socore 1065 May 22 23:57 0010_input_hhbeats.conf
-rw-r--r-- 1 logstash socore 206 May 22 23:57 9999_output_redis.conf
# ls -la /opt/so/conf/logstash/pipelines/search
total 44
drwxr-xr-x 2 logstash socore 4096 May 29 23:42 .
drwxr-xr-x 4 logstash socore 4096 May 29 23:42 ..
-rw-r--r-- 1 logstash socore 180 May 29 23:42 0900_input_redis.conf
-rw-r--r-- 1 logstash socore 372 May 29 23:42 9000_output_zeek.conf
-rw-r--r-- 1 logstash socore 351 May 29 23:42 9002_output_import.conf
-rw-r--r-- 1 logstash socore 342 May 29 23:42 9034_output_syslog.conf
-rw-r--r-- 1 logstash socore 392 May 29 23:42 9100_output_osquery.conf
-rw-r--r-- 1 logstash socore 341 May 29 23:42 9400_output_suricata.conf
-rw-r--r-- 1 logstash socore 370 May 29 23:42 9500_output_beats.conf
-rw-r--r-- 1 logstash socore 338 May 29 23:42 9600_output_ossec.conf
-rw-r--r-- 1 logstash socore 359 May 29 23:42 9700_output_strelka.conf
2. ใส่ค่าเพิ่มใน /opt/so/saltstack/local/pillar/global.sls
logstash:
pipelines:
manager:
config:
- so/0009_input_beats.conf
- so/0010_input_hhbeats.conf
- so/9999_output_redis.conf.jinja
search:
config:
- so/0900_input_redis.conf.jinja
- so/9000_output_zeek.conf.jinja
- so/9002_output_import.conf.jinja
- so/9034_output_syslog.conf.jinja
- so/9100_output_osquery.conf.jinja
- so/9400_output_suricata.conf.jinja
- so/9500_output_beats.conf.jinja
- so/9600_output_ossec.conf.jinja
- so/9700_output_strelka.conf.jinja
3. restart logstash
# so-logstash-restart
4. restart elasticsearch
# so-elasticsearch-restart
====located for salt pipeline config
/opt/so/saltstack/default/salt/logstash/pipelines/config/so
===>after configure pipeline into global.sls then docker will start on choose pipeline and keep configure on path below.
/opt/so/conf/logstash/pipelines/search
===docker command check inspect
docker inspect so-logstash
เท่านี้พวก log ใน dashboard kibana ก็จะแสดงขึ้นมาครับผม