syslog-ng acts as the central receiver for logs transmitted by network switches and other devices.
Installation
Install syslog-ng using your package manager:
Edit the main configuration file:
Store received logs locally
destination d_local { file("/var/log/network/${YEAR}-${MONTH}-${DAY}"); };
Forward logs to Logstash on UDP port 5144
destination d_logstash { udp ("10.120.248.132" port(5144)); };
Combine source and destinations
log { source(s_remote); destination(d_local); destination(d_logstash); };
</div>After configuration, configure your network switches to send logs to this server's IP address.
ELK Stack Installation (Non-Clustered)
--------------------------------------
The ELK stack combines three components:
- **Elasticsearch**: Distributed search and analytics engine for storage and analysis
- **Logstash**: Log processing pipeline for collection, filtering, and forwarding
- **Kibana**: Web-based interface for visualizing and exploring log data
### 1. Download Components
Download version 6.3.0 of all components (version consistency is critical):
- Elasticsearch: https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-6.3.0.tar.gz
- Kibana: https://artifacts.elastic.co/downloads/kibana/kibana-6.3.0-linux-x86\_64.tar.gz
- Logstash: https://artifacts.elastic.co/downloads/logstash/logstash-6.3.0.tar.gz
Transfer files to the server using rz or scp, placing them in /opt/.
### 2. Extract Archives
<div>```
cd /opt
tar -zxvf elasticsearch-6.3.0.tar.gz
tar -zxvf kibana-6.3.0-linux-x86_64.tar.gz
tar -zxvf logstash-6.3.0.tar.gz
ELK requires JDK 1.8 or later. Install OpenJDK:
Edit the configuration file:
Background mode
/opt/elasticsearch-6.3.0/bin/elasticsearch -d
</div>Stop Elasticsearch:
<div>```
ps -ef | grep elasticsearch
kill -9 <pid>
5. Configure and Start Kibana
Edit the configuration file:
Background mode
nohup /opt/kibana-6.3.0-linux-x86_64/bin/kibana &
</div>Stop Kibana:
<div>```
ps -ef | grep kibana
kill -9 <pid>
Create a pipeline configuration file:
Start Logstash:
Background mode
nohup /opt/logstash-6.3.0/bin/logstash -f /opt/logstash-6.3.0/config/switch-pipeline.conf &
</div>Stop Logstash:
<div>```
ps -ef | grep logstash
kill -9 <pid>
Check Elasticsearch indices:
- Navigate to Kibana web interface
- Create an index pattern matching your logs (e.g., network-log-*)
- Select the appropriate timestamp field
- View logs in the Discover section
Note: The time range selector in Kibana uses your browser's local time. If searching for historical logs, adjust the range accordingly.
8. Secure Kibana with Authentication
Use Nginx as a reverse proxy to add basic authentication.
Install htpasswd tool:
location / {
auth_basic "Kibana Authentication Required";
auth_basic_user_file /etc/nginx/passwd/kibana.passwd;
proxy_pass http://localhost:5602;
proxy_redirect off;
}
}
</div>Update Kibana to run on alternate port:
<div>```
vi /opt/kibana-6.3.0-linux-x86_64/config/kibana.yml