Building a Centralized Log Collection System with syslog-ng and ELK Stack

syslog-ng acts as the central receiver for logs transmitted by network switches and other devices.

Installation

Install syslog-ng using your package manager:

Edit the main configuration file:

Store received logs locally

destination d_local { file("/var/log/network/${YEAR}-${MONTH}-${DAY}"); };

Forward logs to Logstash on UDP port 5144

destination d_logstash { udp ("10.120.248.132" port(5144)); };

Combine source and destinations

log { source(s_remote); destination(d_local); destination(d_logstash); };


</div>After configuration, configure your network switches to send logs to this server's IP address.

ELK Stack Installation (Non-Clustered)
--------------------------------------

The ELK stack combines three components:

- **Elasticsearch**: Distributed search and analytics engine for storage and analysis
- **Logstash**: Log processing pipeline for collection, filtering, and forwarding
- **Kibana**: Web-based interface for visualizing and exploring log data

### 1. Download Components

Download version 6.3.0 of all components (version consistency is critical):

- Elasticsearch: https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-6.3.0.tar.gz
- Kibana: https://artifacts.elastic.co/downloads/kibana/kibana-6.3.0-linux-x86\_64.tar.gz
- Logstash: https://artifacts.elastic.co/downloads/logstash/logstash-6.3.0.tar.gz

Transfer files to the server using rz or scp, placing them in /opt/.

### 2. Extract Archives

<div>```
cd /opt
tar -zxvf elasticsearch-6.3.0.tar.gz 
tar -zxvf kibana-6.3.0-linux-x86_64.tar.gz
tar -zxvf logstash-6.3.0.tar.gz

ELK requires JDK 1.8 or later. Install OpenJDK:

Edit the configuration file:

Background mode

/opt/elasticsearch-6.3.0/bin/elasticsearch -d


</div>Stop Elasticsearch:

<div>```
ps -ef | grep elasticsearch
kill -9 <pid>

5. Configure and Start Kibana

Edit the configuration file:

Background mode

nohup /opt/kibana-6.3.0-linux-x86_64/bin/kibana &


</div>Stop Kibana:

<div>```
ps -ef | grep kibana
kill -9 <pid>

Create a pipeline configuration file:

Start Logstash:

Background mode

nohup /opt/logstash-6.3.0/bin/logstash -f /opt/logstash-6.3.0/config/switch-pipeline.conf &


</div>Stop Logstash:

<div>```
ps -ef | grep logstash
kill -9 <pid>

Check Elasticsearch indices:

  1. Navigate to Kibana web interface
  2. Create an index pattern matching your logs (e.g., network-log-*)
  3. Select the appropriate timestamp field
  4. View logs in the Discover section

Note: The time range selector in Kibana uses your browser's local time. If searching for historical logs, adjust the range accordingly.

8. Secure Kibana with Authentication

Use Nginx as a reverse proxy to add basic authentication.

Install htpasswd tool:

location / {
    auth_basic "Kibana Authentication Required";
    auth_basic_user_file /etc/nginx/passwd/kibana.passwd;
    proxy_pass http://localhost:5602;
    proxy_redirect off;
}

}


</div>Update Kibana to run on alternate port:

<div>```
vi /opt/kibana-6.3.0-linux-x86_64/config/kibana.yml

Tags: elasticsearch Logstash kibana syslog-ng elk-stack

Posted on Wed, 30 Sep 2026 16:18:45 +0000 by snk