Тёмный

Best SIEM Logging With Graylog - Routing SIEM Logs with Graylog! 

Taylor Walton
Подписаться 17 тыс.
Просмотров 14 тыс.
50% 1

Join me as we continue on to Phase 5 of the World's Best SIEM Stack Series, parsing and routing our received Wazuh alerts with Graylog!.
Blog Post: / part-5-intelligent-sie...
Contact Me: taylor.walton@socfortress.co
LinkedIn: / socfortressmdr
Twitter: / socfortress
Our Blog: / socfortress
Buy Me A Coffee: bit.ly/3woh21M
Security Operations Center as a Service: www.socfortress.co/
Free For Life Tier: www.socfortress.co/trial.html
Professional Services: www.socfortress.co/ps.html
Discord Channel: / discord
Series Playlist: • World's Best SIEM Stack

Наука

Опубликовано:

 

4 ноя 2022

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 25   
@iGarrettt
@iGarrettt 10 месяцев назад
I've hunted and hunted for an ELI5 video on greylog and this is it. Thank you for such a fantastic and detailed series
@enderst81
@enderst81 Год назад
Great series thanks!
@eliasantoniadis8556
@eliasantoniadis8556 Год назад
Finally! Amazing!
@eldecloud
@eldecloud Год назад
Great and clean (for taking a shower before rec the video) explanation! 😂
@vadimkutia6516
@vadimkutia6516 Год назад
Thanks for the video, I enjoyed watching all the parts! I don't fully understand why we collect logs using greylag and wazuh agents together? Why not use only one thing? Please explain this point in more detail.
@ArcamNight
@ArcamNight 11 месяцев назад
Yeah also I don't know why he use both 😅
@Damielsestrem
@Damielsestrem Год назад
hi Taylor, is it possible to add 2factor for wazuh login?
@perfecto25
@perfecto25 9 месяцев назад
btw, to route events into a stream, you dont needba custom field at Input level goto Streams, create new stream rule, gl2_source_input= GUID of the Input you can find guid on input section of cfg
@hspcd
@hspcd 10 месяцев назад
Taylor - is it possible to implement multi-tenancy where a tenant is a customer?
@mikegrok
@mikegrok Год назад
At the end, you probably mean no more than 1000 unique keys per index. Other reasons to create different indexes for different uses and sources is for security and response time reasons. For instance the help desk may need to be able to see the time stamp of the most recent login and failure to login, as well as the source and attempts in the last 24 hours without being able to see who sent emails to HR.
@xinghe3780
@xinghe3780 Год назад
how to generate ssh log
@Huelilik
@Huelilik Год назад
Woow a very amazing video adds to my knowledge about this wazuh. I want to ask sir, I have WHM Root Server, Debian OS which is very outdated and does not support wazuh Agnet. We couldn't update it because of the many third-party apps that might not run when I run the update. (I know this is very fatal but I don't dare to take the risk when updating the OS). which is my question. do you have a solution for monitoring the server without installing the agent on the debian server?? is a reverse proxy with a server that supports wazuh agent possible?? ( on the reverse proxy I will install a firewall to secure the website and the wazuh agent for active monitoring and response) . Please advice from you sir. Best Regards
@eliasantoniadis8556
@eliasantoniadis8556 Год назад
You can send syslog logs to wazuh without agent
@Huelilik
@Huelilik Год назад
@@eliasantoniadis8556 how do you do it, can you recommend any documentation or articles about it?
@williamice5965
@williamice5965 Год назад
Hello 👋, I’m new here you just get a new subscriber, please I do have questions do you know any php script to block a browser from visiting your site for example I want to block Firefox user from visiting my site. Which will display this browser not supposed. Please I do need help 🙏
@robert4049
@robert4049 Год назад
I followed the instructions, but I'm getting the below when go to create a parser on the input in grey log? Elasticsearch exception [type=illegal_argument_exception, reason=key [types] is not supported in the metadata section]. Cluster Version: "number" : "7.10.2", ii graylog-4.3-repository 1-6 all Package to install Graylog 4.3 GPG key and repository ii graylog-integrations-plugins 4.3.15-1 all Graylog Integrations plugins ii graylog-server 4.3.15-1 all Graylog server ii mongodb-database-tools 100.7.0 amd64 mongodb-database-tools package provides tools for working with the MongoDB server: ii mongodb-org 4.4.21 amd64 MongoDB open source document-oriented database system (metapackage) ii mongodb-org-database-tools-extra 4.4.21 amd64 Extra MongoDB database tools ii mongodb-org-mongos 4.4.21 amd64 MongoDB sharded cluster query router ii mongodb-org-server 4.4.21 amd64 MongoDB database server ii mongodb-org-shell 4.4.21 amd64 MongoDB shell client ii mongodb-org-tools 4.4.21 amd64 MongoDB tools
@vishakjaisimha5842
@vishakjaisimha5842 3 месяца назад
did u find the fix i struggling with the same issue and are u getting any logs from sysmon in wazuh my thing is blank
@MrGhost-pj8lf
@MrGhost-pj8lf 2 месяца назад
@@vishakjaisimha5842 go to /etc/wazuh-indexer directory and edit opensearch.yml file and change "compatibility.override_main_response_version: false". Then restart the wazuh-indexer and also graylog server
@enarcee1
@enarcee1 Год назад
Hey Taylor.. been following along with this (excellent) series and have hit a hurdle at this stage. When applying the JSON exractor to both win and linux agent logs I get a processing error in Graylog: gl2_processing_error Replaced invalid timestamp value in message with current time - Value caused exception: Invalid format: "2023-05-30T04:07:00.230+0000" is malformed at "T04:07:00.230+0000 Couple of questions: [1] is this the aright place to post issues? If not can you point me there. [2] have you come acoss this issue previously? graylog-server 5.1.1-1 wazuh-indexer 4.4.5-1 ubuntu 22.04.2 LTS Added 20230531 - I note at ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-ZDL4MUxtIrY.html in the video you are expereincing same gl2_processing_error. btw - not trying to be picky, just trying to understand.
@ohioguy007
@ohioguy007 Год назад
@taylorwalton_socfortress In this video, you created the "wazuh-alerts-socfortress_" index. How do you get this index to replace the default "wazuh-alerts-" index in wazuh dashboard so you can visualize the data?
@joerg.schindler
@joerg.schindler Год назад
Hey Metthew, you can change the Default index Stack Management => Advanced Settings. However, I do not recommend using the Wazu Dashboard to visualize your data if you are using Graylog. The problem is the underscore separating the fields e.g. agent_name. By default the Wazuh indexer uses a dot to separate the fields agent.name. There seems to be a way to swap the dot with the underscore in Graylog, but I haven't figured out how to do that yet. I asked the Wazuh team if this could be changed in the dashboard, which is currently not possible, except to "recode" the dashboard. Maybe they want to fix the problem soon.
@DeadlyDragon_
@DeadlyDragon_ 4 месяца назад
@@joerg.schindlerMy solution was to setup a separate opensearch cluster that graylog uses, and to feed graylog the wazuh data via syslog in json format. This way I get the features of wazuh and graylog together.
Далее
Wazuh Install - Worlds Best OpenSource EDR!
26:23
Просмотров 27 тыс.
💜☀️✨
00:47
Просмотров 128 тыс.
11. Graylog 3.0 Streams and Indices
14:12
Просмотров 18 тыс.
The Graylog Goal and Inputs
8:46
Просмотров 6 тыс.
Adding Agentic Layers to RAG
19:40
Просмотров 16 тыс.
How to Send Unifi Logs to a Syslog Server
10:40
Просмотров 22 тыс.
OZON РАЗБИЛИ 3 КОМПЬЮТЕРА
0:57
Просмотров 47 тыс.
ПОКУПКА ТЕЛЕФОНА С АВИТО?🤭
1:00