Graylog: Your Comprehensive Guide to Getting Started Open Source Log Management

Graylog: Your Comprehensive Guide to Getting Started Open Source Log Management

Lawrence Systems

1 год назад

159,516 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

zhimiao li
zhimiao li - 22.11.2023 12:25

great video

Ответить
doman tlen
doman tlen - 22.11.2023 01:07

But 1514 is unencrypted right?, I mean syslog data are being sent "naked"? It means that network connection should be trustfull. Like separate VLAN or something?

Ответить
Abhishek Jain
Abhishek Jain - 01.11.2023 11:05

Does gray log provide functionality in addition to wazuh ? Or they are same.

Ответить
Riko Vejgaard
Riko Vejgaard - 31.10.2023 17:59

Thanks for the wonderful and easy to follow toturial. - Do you use Greylog at Lawrence Systems to collect logs for all of your clients (Fleet)?

Ответить
Quarry Rats
Quarry Rats - 28.10.2023 10:28

Great video, love the platform and install guide!

What variable can I use in the email notification template to see the source IP of the device that generated the log entry? I tried using ${field.src_ip} but it just shows blank in the email.

Ответить
Sonali Gupta
Sonali Gupta - 27.10.2023 20:01

Saw in the latest docs that the virtual appliances is no longer available, neither able to find the OVA image.
Not sure if its possible to install this in docker on a mac setup.

Ответить
Claude-Alexandre Rochat
Claude-Alexandre Rochat - 26.10.2023 23:27

Great job 🎉

Ответить
Neelesh Gurjar
Neelesh Gurjar - 11.10.2023 16:50

Amazing information. Thanks!
How can I setup Graylog cluster with High Availability and scalable?

Ответить
Leonardo Nogueira
Leonardo Nogueira - 06.10.2023 07:34

This is really nice. Thanks for sharing.

Ответить
severgun
severgun - 04.10.2023 10:44

For modern setups worth to mention

1) there is SSL support but in docker it needs to pass some additional environment vars and java keystore
2) new mongo releases need CPUs with AVX. This can be stopping factor
3) for times zones as I remember you need to add _ROOT_.
GRAYLOG_ROOT_TIMEZONE

Ответить
Mode44
Mode44 - 02.10.2023 18:19

Having multiple issues with docker compose erroring on the depends_on section of the YAML, first error is needs to be an array and then values need to be a string, any ideas ?

Ответить
perfecto25
perfecto25 - 29.09.2023 21:53

very helpful thank you

Ответить
Samuele Annulli
Samuele Annulli - 27.08.2023 01:34

hi good evening, very good works...please a question?...how do yo do your prompt console??? many thanks in advance

Ответить
Battleripper
Battleripper - 08.08.2023 15:46

BUT
How do I make a cluster system with redundancy purposes

Ответить
Boris S
Boris S - 28.07.2023 09:47

is any specific reason do you using opensearch instead elasticsearch ?

Ответить
Prashanth G
Prashanth G - 25.07.2023 19:47

This is very good!👏

Ответить
lalala987
lalala987 - 25.07.2023 14:08

@Lawrencesystems: did you get a new t-shirt? :)

Ответить
MonheimX9
MonheimX9 - 19.07.2023 14:11

I've more than 25 docker containers running on few different VMs, I'm no expert in docker but not really a newbie either
But starting Graylog? I just can't do it
The way they implemented the $USER is beyond my understanding
Keep getting stuck at this error when Graylog is starting:
ERROR org.graylog2.bootstrap.CmdLineTool - Couldn't load configuration: Properties file /usr/share/graylog/data/config/graylog.conf doesn't exist!
(And yes it exist, and it is mapped correctly)

I've tried to set user variables, tried to change directly the mounted directory ownership to 1100:1100
I've tried with other versions of docker-compose
Tried also changing the owner to docker:docker

Executed multiple times that "sudo usermod -aG docker $USER"
Rebooted the server, tried other mounting points that are not in the /home directory
Nothing works

Sorry but the Graylog docker image is broken for me (and no I'm not using snap docker package even tho I'm running on Ubuntu Server)

Thank you for the tutorial but sadly I might have to many skill issues to solve this

Ответить
Toon Proost
Toon Proost - 17.07.2023 13:52

Great guide, thanks for the info. Tip for those who use proxmox as vm host. Put your CPU in Host mode as otherwise mongodb will not work.

Ответить
Nostang3
Nostang3 - 10.07.2023 22:04

Wish you would do a install version of this on scale. It seems impossible to get it to work. Everyone and their mom is using yaml and scale doesn't.

Ответить
Gregory Krisa
Gregory Krisa - 07.07.2023 04:27

It’s odd I set this up and found that windows 11 default firewall blocks port 9000 so I thought it wasn’t working and then decided to try my phone and it was working except that some reason my password I placed was not working.

Ответить
Rob Pungello
Rob Pungello - 27.06.2023 05:05

One thing I cannot for the life of me figure out is how to use NFS to store the actual log data (opensearch). If you try and use docker-compose to store the data on an NFS volume, the container fails to launch as it seems the image is trying to run chown on the data storage directory, which I guess nfs doesn't allow.

Ответить
Stephen
Stephen - 09.06.2023 04:24

Do a pipeline vidjayo

Ответить
gakky_sensei
gakky_sensei - 28.05.2023 07:09

Thanks for the video for deploying graylog. It seems your demo server has 8 core 4GB memory. I know it is for demo purpose. But how can I calcurate the necessary hardware resource for certain system ?

Ответить
Baku18000
Baku18000 - 27.05.2023 20:15

I may have done something wrong because messages are only hitting the very last stream/indices I created. In other words, PFsense was the first one created, and messages were hitting it. The last one I created was for a Cisco switch, and now no PfSense messages, but lots of messages to the Cisco switch. Any thoughts on this? Thanks!

Ответить
Hirschy Kirkwood
Hirschy Kirkwood - 27.05.2023 02:22

this was such a fucking mess for me. Once I got permissions all figured out, I found out that mongo 5.0+ required hardware that apperantly my box didn't have, and then I tried to figure out compatability between all three, and i just gave up, it's not worth it for something to needless for me...

Ответить
OthmanEmpire
OthmanEmpire - 26.05.2023 18:16

Thanks for the video =)

Ответить
Ford Crews
Ford Crews - 26.05.2023 00:29

How about a video with a sidecar and windows logs?

Ответить
Davo CC
Davo CC - 24.05.2023 13:39

Minor thing - I'd recommend adding an extra space to the beginning of the echo command at the early stage where you create the SHA256sum for the password - this stops the password being visible in that user's history. Minor thing but I've heard of history files being a juicy target like this.

Ответить
Travis Curley
Travis Curley - 23.05.2023 23:51

Not sure why I keep getting the pwd variable is not set. defaulting to a blank string. Was able to get it running but don't see the web UI as well.

Ответить
Philip Adam
Philip Adam - 23.05.2023 14:20

Really great video, thank you. Very clear, detailed and last but not least: usefull

Ответить
eduitguy
eduitguy - 23.05.2023 08:09

Thanks. Using Grayling but your video showed some great ways to modify it.

And love the glasses look!

Ответить
turbo2ltr
turbo2ltr - 22.05.2023 16:36

So an index is just a way to do high level categorizing/grouping of data sets/sources?

Ответить
Torgny Bjers
Torgny Bjers - 22.05.2023 07:24

Thank you for making this video. I know we all copy and paste at times for expediency. However, to recommend that users do this, in a video, may enforce dangerous behaviors. Should people just have common sense and read the commands before they paste them? Yes, of course. But, hey, that's what we have disclaimers for. "If you feel confident in my instructions, and you are running this in a development environment, you can go ahead and copy and paste these commands into your terminal." Obviously, if your hat is really, really dark, making people dumber is obviously a worthwhile goal.

Ответить
Will Blanton
Will Blanton - 22.05.2023 05:56

Tom, is it recommended to use docker compose for production?

Ответить
Jason Gardner
Jason Gardner - 21.05.2023 14:01

I did this as an assignment a few months before I graduated. I did not set it up on my own server at the time. Thanks for making this video!

Ответить
FrankFix
FrankFix - 20.05.2023 22:53

What about Grafana & Prometheus? What are the differences?

Ответить
severgun
severgun - 20.05.2023 10:13

what about loki?

Ответить
Rob Sexton
Rob Sexton - 19.05.2023 18:11

Just what I needed! Thanks Tom for all you hard work.

Ответить
chswin
chswin - 19.05.2023 16:05

Seq is better…

Ответить
Dushyant Giri
Dushyant Giri - 18.05.2023 05:36

If we are using elastic search then what's the advantage with this tool? Why should we use it?

Ответить
Robert4049
Robert4049 - 17.05.2023 22:18

Is there any way to get UniFi Firewall logs into Graylog?

Ответить
Vladislav Kalashnikov
Vladislav Kalashnikov - 17.05.2023 08:06

Can I attach any dashboard to greylog?

Ответить
Vladislav Kalashnikov
Vladislav Kalashnikov - 16.05.2023 18:31

Hey Tom, could you make a video about zabbix as a comparison. It has pre-defined templates and triggers for the most popular systems, linux, windows, firewalls, etc. Very powerful tool. I would love to see it on your channel. It comes containerized as well.

Ответить
Gary Laser Eyes
Gary Laser Eyes - 16.05.2023 12:19

This turns painful really quick if your processor doesn't support AVX.

Ответить
Baku18000
Baku18000 - 14.05.2023 05:19

Well done - thank you!

Ответить