timmolter / logstash-dfir

Logstash configuration files for analyzing various types of logs

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

logstash-dfir

Logstash configuration files for analyzing various types of logs. These configuration files are provided to analyze various types of log files using logstash, elasticsearch, and kibana.

Whether you are running a full-blown setup of ElasticSearch, Kibana, and log shippers, or a single instance for rapid analysis, these configuration files will help you quickly parse various log files found on system images.

Logstash

Logstash Website

Other Resources

sysforensics GitHub

Related Posts

I'll take some Elasticsearch/Kibana with my Plaso (Windows edition)

Finding the Needle in the Haystack with ELK

Rapid Log Analysis

Do you even Bro, bro?

Utilizing Dictionaries with Logstash

Changelog

07 Jan 2015 - Uploaded logstash dictionaries for HTTP, FTP, and Bro IDS conn log status codes

04 Sep 2014 - Uploaded Bro IDS logs; thanks to team at http://www.appliednsm.com for laying the groundwork

02 Mar 2014 - Added log2timeline logstash config

01 Mar 2014 - Added apache-combined logstash config

22 Feb 2014 - Repository created; uploaded apache-common logstash config.

About

Logstash configuration files for analyzing various types of logs

License:MIT License