Тёмный
Ali Younes
Ali Younes
Ali Younes
Подписаться
Hello Everyone,

My name is Ali, I am a Network Analyst. I love learning networking technologies and sharing what I learn with the IT community. I earned a couple of Cisco CCNA certificates, Fortinet NSE4, and am currently working on my CCNP studies and network automation with Python.
In this channel, I share what I learn and try to explain things that gave me a hard time so you don't struggle as much 😄

Subscribe and enjoy the learning!
FortiGate SNMP Monitoring with Logstash
21:09
8 месяцев назад
Build a Custom Docker Image for Logstash
15:37
10 месяцев назад
Enrich your Data in Elasticsearch
14:43
Год назад
Monitor Logstash with Metricbeat
12:22
Год назад
Enable Kibana Monitoring
6:24
2 года назад
Visualizing FortiGate Logs on Kibana
11:37
2 года назад
Monitor Elasticsearch with Metricbeat
19:54
2 года назад
Комментарии
@ihsanurrahman3348
@ihsanurrahman3348 5 дней назад
i wish there were a like button which can generate tons of likes..i would do that on this video!! you have solve my biggest problem!!thanks a lot boss
@AliYounesGo4IT
@AliYounesGo4IT 4 дня назад
Glad it helped!
@schoonees
@schoonees 8 дней назад
Hi Ali, fantastic video - works like a charm. Thx for the effort. I have one or two questions regarding adding additional containers to the docker-compose file. If i add additional containers, i get the following error, validating /home/test/elk/docker-compose.yml: services.logstash Additional property filebeat is not allowed. Can file beat just be added as a separate container instead of adding it to the docker-compose file?
@AliYounesGo4IT
@AliYounesGo4IT 6 дней назад
You can add it as a separate container, but I think the error is because Filebeat has to be on the same level as Logstash under the "services" key in the docker-compose.yml file.
@paliwanacho8996
@paliwanacho8996 9 дней назад
Hi, ca we send log from fortigate directly to logstash/elasticsearch withtout filebeat? I mean, Why do most tutorials always use Filebeat?
@AliYounesGo4IT
@AliYounesGo4IT 6 дней назад
Yes you can send to Logstash without Filebeat. I have this tutorial explaining how to install Logstash and send Fortigate logs to it: ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-Tp5dI-GDerM.htmlsi=9XJLRCBk_R91-BZk
@elabeddhahbi3301
@elabeddhahbi3301 11 дней назад
i have question about ILM is it possible to create lifecycle policy for index pattern not just an index
@AliYounesGo4IT
@AliYounesGo4IT 9 дней назад
I made a video on ILM, check it out here: ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-Ybbk44mkOE0.htmlsi=X9WjOrNFA6Mv106e
@alkhateeeb
@alkhateeeb 13 дней назад
Thank you, Ali, for this video, useful one.
@ivanlawrence2
@ivanlawrence2 15 дней назад
Still valid in 2024! Thank you for the help!
@issamzgybi9761
@issamzgybi9761 17 дней назад
thank youuuu brother ❤
@OmegaScouter
@OmegaScouter 22 дня назад
I almost gave up installing ELK 8. Thank you very much for the straight and forward video. The only difference I have to make is setting cluster name and keeping the node-name disabled. Much respect
@WeAreAllStarDust-r3w
@WeAreAllStarDust-r3w 23 дня назад
thank you! :D i have stuck configuring kibana and elastic search for weeks Thanks again for the clear guidance
@razmus9708
@razmus9708 Месяц назад
Just what I needed - Brilliant!
@adelodeh8086
@adelodeh8086 Месяц назад
Amazing video!! thank you Ali
@bucksera475
@bucksera475 Месяц назад
wonderfull video
@ananyayechuri320
@ananyayechuri320 Месяц назад
Hey, I was able to download and setup filebeat and it showed me that kibana dashboard must be running and reachable but when I refresh the page the logs section shows me that I still need to install filebeat which I have already done
@samsal073
@samsal073 Месяц назад
Hi Ali, Do you think ElasticSearch can be used for documents archiving and records management. I work for engineering company where project can produce 10s of thousands of documents . All those need to be archived provided retention schedule before records\files are destroyed (deleted from they system with log documenting the destruction event).
@user-bw9kl7cn7o
@user-bw9kl7cn7o Месяц назад
Python errors with elastalerts2! Its not working! And remove dislike wtf?
@hosseinasgari1489
@hosseinasgari1489 Месяц назад
thanks you man 🙏
@danstermeister
@danstermeister Месяц назад
that was the clearest explanation I've seen for timelion- I wish I had seen it years ago!😄
@hoseinabdollahi
@hoseinabdollahi Месяц назад
Very great job. Sufficient and very good explanations. very practical
@shaclo
@shaclo Месяц назад
That is really helpfull !!!
@ahmed_mansour5
@ahmed_mansour5 Месяц назад
Thanks a lot for the great explanation! It was really useful as it gave the two ways to deploy ILM (with and without rollover)
@zhajikun5309
@zhajikun5309 Месяц назад
I run your docker-compose file but get this error in Kinaba: FATAL Error: [config validation of [xpack.encryptedSavedObjects].encryptionKey]: value has length [16] but it must have a minimum length of [32].
@wbarbosabr
@wbarbosabr Месяц назад
ENCRIPTION_KEY on .env should have at least 32 chars, the default value <encriptation_data> has 16...
@as-saidiabderrahmane9493
@as-saidiabderrahmane9493 2 месяца назад
MAD RESPECT!! Clear explanations, well-paced tutorials, and incredibly useful content. Big props to you Ali for making complex topics so accessible and engaging. waiting for more about elastic stack kafka, load balancing, reverse proxies, integration with TheHive, Cortex... Keep up the fantastic work may Allah bless you! ❤🙏
@user-ny1up4xr2r
@user-ny1up4xr2r 2 месяца назад
Despite configuring SSL certificates why it appears insecure n the browser?????????????????????????????????
@0xfaizan
@0xfaizan 2 месяца назад
awesome, ill wait for next lectures
@vector1one
@vector1one 2 месяца назад
followed this but every time I join a node it crashes the master, if I restart the master it crashes the node. any ideas?
@bnayakqs
@bnayakqs 2 месяца назад
Thanks a ton for this, was looking for this for a while.
@venkataramesh6263
@venkataramesh6263 2 месяца назад
Here in this video , Can you show me how to extract ip address and assign to other field ?because i want to populate that ip in the other slot
@junner13
@junner13 2 месяца назад
Im confused, what's the difference between elastic agent and apm agent or are these the same?
@user-wt8nd9fg8y
@user-wt8nd9fg8y 2 месяца назад
Great what if i have multiple elasticsearch node, How we can define in kibana.yml
@alexisisraeldelarosamilan1137
@alexisisraeldelarosamilan1137 3 месяца назад
my logstash cannot conect to elastic.. i already put in false the security... logs in logstash are like this: [2024-06-07T08:06:29,273][WARN ][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error. {:url=>"localhost:9200/", :error_type=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError, :error=>"Elasticsearch Unreachable: [localhost:9200/][Manticore::SocketException] Connection refused (Connection refused)"}
@saintvittsdance
@saintvittsdance 3 месяца назад
Thank you!
@Rackhage
@Rackhage 3 месяца назад
Hey man, I don't get data on some fields and I miss data in the dashboard. How do I resolve this?
@danialwaris1790
@danialwaris1790 3 месяца назад
Deserve an applause. you cover all basic details to setup the elasticsearch and kibana,
@birgaripkul1612
@birgaripkul1612 3 месяца назад
Thank you very much for your great tutorial. Even if the Elastic documentation explains similar steps but there were many steps not working, but you shown them practically.
@silentreader8426
@silentreader8426 3 месяца назад
which one is better depends on performance, send log via filebeat or via logstash?
@junner13
@junner13 3 месяца назад
i cant understand the difference between logstash and filebeat, why not using just filebeat instead of logstash?
@silentreader8426
@silentreader8426 3 месяца назад
same with me lol!
@Rackhage
@Rackhage 3 месяца назад
I miss a lot of fields! How do I get these?
@vullifamily6709
@vullifamily6709 3 месяца назад
How to resolve the hot node disk is full I have unassigned shards and the indices health is red
@patilavinash7406
@patilavinash7406 3 месяца назад
Hi I want to install ELK on a test/production server can you please me for that
@ibnudafa8772
@ibnudafa8772 3 месяца назад
i have error : org.jruby.exceptions.SystemExit: (SystemExit) exit at org.jruby.RubyKernel.exit(org/jruby/RubyKernel.java:808) ~[jruby.jar:?] at org.jruby.RubyKernel.exit(org/jruby/RubyKernel.java:767) ~[jruby.jar:?] at usr.share.logstash.lib.bootstrap.environment.<main>(/usr/share/logstash/lib/bootstrap/en vironment.rb:90) ~[?:?]
@AmolNagotkar
@AmolNagotkar 3 месяца назад
i want to add fleet server hosts as http. is it possible ? I am doing everything on localhost
@sasikanth1329
@sasikanth1329 3 месяца назад
Hi ali... I am facing an issue.... After following these steps i am unable to connect to elasticsearch search from my logstash server.... Can you help
@seniortaco100
@seniortaco100 3 месяца назад
Nice Vid Ali. I've installed Fleet and some Integrations. But when I try a CISCO FTD, the installation gets completed, No errors observed. Yet the Data Streams are not created. Any suggestion? I am supposed to receive the logs into a Ingestion Server with the Elastic Agent installed and the FTD sends the logs to the Ingestion server. In my integration I am using the IP address of the Ingestion server port 9003. The Ingestion server windows firewall has the UDP port opened. All this is on Windows btw. I use the same Agent policy for both the Windows OS and the Cisco devices. I tried to create a new Cisco policy to separate the logs, but then it tries to install the Agent on the Ingestion server which has the Elastic Agent already installed for the other Integrations. I even changed the Namespace on the Integration settings to user other name than "default" and eve tried with "default". Same results whatsoever. Thanks for your help if at all possible.
@borg_wow
@borg_wow 3 месяца назад
We just moved from a pfsense netgate + dell switch setup to a full 2x fortigate 100f in HA + 3 stacked Fortiswitches so, trying to learn as much as I can about this environment.
@alfiyass-cb4xt
@alfiyass-cb4xt 4 месяца назад
ELK version upgradation please please to V 8.12.0
@JuanAndreas-co5kl
@JuanAndreas-co5kl 4 месяца назад
why does this not work for me lol. I can't access kibana even after following all the steps
@JuanAndreas-co5kl
@JuanAndreas-co5kl 4 месяца назад
this doesnt work for me and i cant even access my first node or kibana anymore
@user-ul4uv6xi7e
@user-ul4uv6xi7e 4 месяца назад
Great!
@bilelbenzerafa253
@bilelbenzerafa253 4 месяца назад
كل الشكر و التقدير على هدا العمل الجميل شكرا اخي
@cristianleitonvalencia8019
@cristianleitonvalencia8019 4 месяца назад
I have errors: "stacktrace": ["java.net.UnknownHostException: es01" "stacktrace": ["java.net.UnknownHostException: es02" "stacktrace": ["java.net.UnknownHostException: es03" Help me please!