Тёмный

Graylog: Your Comprehensive Guide to Getting Started Open Source Log Management 

Lawrence Systems
Подписаться 339 тыс.
Просмотров 171 тыс.
50% 1

Опубликовано:

 

26 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 204   
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
My Graylog 5 Forum Post with commands lawrence.video/graylog5
@fxdtech
@fxdtech Год назад
Do you know of a way to get the Wazuh4.4.1 docker deployment {using their cert generator} along side with graylog5.0?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
@@fxdtech I do not.
@fxdtech
@fxdtech Год назад
@@LAWRENCESYSTEMS Thank you for your reply man! Do you know where you could possibly point me in the right direction - I have been chasing my tail any insight would be greatly appreciated.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
@@fxdtech I don't use it so I don't know
@crawshaws1234
@crawshaws1234 Год назад
Quick Question: What shell is that? I like the wrapping around for the command.
@richardahlquist5839
@richardahlquist5839 Год назад
Tom, thank you. This is what makes you stand out. You dont explain only how but also why. So many things now people write a guide only on how.
@mt_kegan512
@mt_kegan512 Год назад
I would vote that once the technology exists and is safe, we clone Tom first!
@ketatgenhorst
@ketatgenhorst Год назад
I have been a linux admin for about as long as linux admins have been a thing, but I have managed to avoid Docker for some reason. I saw that this was on docker and it was a project I wanted to try... my first instinct was "No, find the source" but I decided to give it a shot. Thanks for making this really easy.
@davocc2405
@davocc2405 Год назад
Minor thing - I'd recommend adding an extra space to the beginning of the echo command at the early stage where you create the SHA256sum for the password - this stops the password being visible in that user's history. Minor thing but I've heard of history files being a juicy target like this.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
Yeah, good point for sure. Running though the bash history is a great info gathering technique.
@davocc2405
@davocc2405 Год назад
@@LAWRENCESYSTEMS I think I learned that method on your channel actually, you guys are doing God's work here that's for sure
@CharlesHayden
@CharlesHayden 3 месяца назад
Great tip as I was wondering how to avoid that opsec issue after looking the my history
@NameThievery
@NameThievery Год назад
I did this as an assignment a few months before I graduated. I did not set it up on my own server at the time. Thanks for making this video!
@redstonemason
@redstonemason Год назад
Must have paused and rewound the video about 100 times but got my pfsense logs flowing to a graylog testbed as per this video. Requested a login acct as "mark" on your Forum to post some further questions. Great video.
@thorismud
@thorismud Год назад
Great guide, thanks for the info. Tip for those who use proxmox as vm host. Put your CPU in Host mode as otherwise mongodb will not work.
@maverick173
@maverick173 Год назад
This was great. Thank you Lawrence for taking the time to do this for us. I for one am adding this to the list of things to build this weekend.
@leadwhite1249
@leadwhite1249 Год назад
Thanks for the updated tutorial! I set up graylog using docker compose a few months back, and followed the old video for the in-app setup part. It's great for folks to have an up-to-date version of the instructions. For anyone looking to set this up - inevitably some servers will disagree about the timezone, so even if you set your user and timezone correctly, its worth having a pipeline that can adjust a source between UTC and local time.
@Clarence-Homelab
@Clarence-Homelab Год назад
I'm just guessing but maybe making sure the timezone set in the docker compose environment variable matches that of the server docker is running on is a good place to start. :)
@SiBex_ovh
@SiBex_ovh Год назад
14:08 you can mark, that new user with own timezone will be see logs with corrected time and mark diff that admin see utc. This video is better then previous. Good job and I hope you create a video about extractors.
@SiBex_ovh
@SiBex_ovh Год назад
and, where you have a extractors for unifi ?
@Zaf9670
@Zaf9670 Год назад
So Tom really just made the video to get his shirt fixed. I knew he didn't just make videos for education alone! 😂
@d00dEEE
@d00dEEE Год назад
Graylog will probably just send him a patch.
@petersimmons7833
@petersimmons7833 Год назад
And an excellent exchange of about 20 hours to make the video in exchange for a shirt, too
@eduitguy9016
@eduitguy9016 Год назад
Thanks. Using Grayling but your video showed some great ways to modify it. And love the glasses look!
@moelassus
@moelassus Год назад
Fantastic tutorial, Tom. I'd love to see how to bring in pfBlocker logs into Graylog.
@sublimeghost
@sublimeghost Год назад
I was literally about to go over your previous video for exactly this. Great video as always! Thanks Tom!
@mt_kegan512
@mt_kegan512 Год назад
Haven't watched the video YET.... But love the "tutorial" image on the thumbnail. Nice touch!
@robsexton4181
@robsexton4181 Год назад
Just what I needed! Thanks Tom for all you hard work.
@Hossimo
@Hossimo Год назад
Strange, last night I finally got around to starting work on testing a Graylog server. noticed your instructions were for V4, and decided I would do get the docker image working today.. now Look at this! what timing.
@alex.prodigy
@alex.prodigy Год назад
Thank you Tom , awesome video ... graylog looks very interesting as a centralized logging solution
@ChrisHolzer
@ChrisHolzer Год назад
I'd really like to use it but the fact that "log view" is behind the enterprise version paywall is just insane. will stay with Grafana Loki as logs are just so much easier to read there - such a shame for homelab users like me.
@nicoladellino8124
@nicoladellino8124 Год назад
Very useful video, THX Lawrence .
@cooki3cutt3r13
@cooki3cutt3r13 Год назад
super awesome video, I'm a huge fan of graylog.
@冇人知我名
@冇人知我名 4 месяца назад
great tutor, i see the workflow and what it can do.
@derekp6636
@derekp6636 Месяц назад
Thanks for the recommendations! Was a bit finicky but got it running on my proxmox cluster and ingesting logs from the xigmanas box now! nice to have logs I can search instead of losing on reboot. Anyone else going thru the install make sure you set the CPU up to at least x86_64_v3 for the intruction set for mongodb. Took me a bit to find the error.
@gringo533
@gringo533 3 месяца назад
Great quick tutorial! However the part I am most struggling with is the connection between inputs, streams, indices and extractors. A comprehensive overview of the architectural model of Graylog would be much appreciated.
@ralienpp
@ralienpp 9 месяцев назад
Thanks for the great tutorial! I would be interested in a discussion about Sentry - an open source tool for catching unhandled exceptions, collecting related context data and alerting the developers. It seems that some of this logic can be implemented with Graylog, and I was wondering whether it makes sense to use both systems, or if one would suffice.
@domantlen6231
@domantlen6231 10 месяцев назад
But 1514 is unencrypted right?, I mean syslog data are being sent "naked"? It means that network connection should be trustfull. Like separate VLAN or something?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 10 месяцев назад
In the demo I was sending logs unencrypted to that port. Graylog supports some encrypted protocols forlogs but not all devices support sending them.
@keyboard_g
@keyboard_g Год назад
Ubuntu redirecting Apt Get commands to Snap Install is so dishonest. Want to promote snap, fine. Lying to the user should not be tolerated.
@cranil
@cranil Год назад
One of the reasons I moved all my servers to debian
@odnankenobi
@odnankenobi 6 месяцев назад
​@@cranil This is the way. Moving to community based distros is going to be the way to go for a lot of people
@beepboopbeepboop190
@beepboopbeepboop190 Год назад
Maybe I missed it but I don't think you mentioned the pros/cons of installing via docker instead of a "normal" install. I'd also be interested in your opinion on graylog vs loki/grafana. Also you're using opensearch and I think elastic was my only option when I set this up and I'm not a fan of elastic -- would be interested in hearing why you chose opensearch. I have graylog running in a proxmox vm that I set up years ago. Struggled to get it setup and configured, I have some ongoing issues where some feeds have accurate times and others have their timestamps in a different timezone, but it feels like such a headache to configure as a hobbyist who doesn't work with it daily. I know there's a lot more I could be getting out of it, but right now it basically sits as a "well if something goes terribly wrong i can search graylog" and that's about the extent of the value I get from it. Thinking about switching to loki/grafana in the hopes the config is easier for someone who doesn't interact with it daily where currently any changes I want to make mean I'm going to spend hours researching the syntax or formatting for graylog. It's 100% lack of familiarity on my part combined with user error but the thought of having to make changes to graylog gives me a headache.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
Docker is easier to use and maintain for Graylog, the Elasitic licence changes as I understand them makes OpenSeach a better choice, Loki looks much more complicated to configure.
@beepboopbeepboop190
@beepboopbeepboop190 Год назад
@@LAWRENCESYSTEMS Thanks Tom! I found Graylog's youtube channel has a video on migrating from elastic to Opensearch so it looks like that might be in my future. Sounds like my hopes on Loki won't likely pan out then haha.
@philipadam8023
@philipadam8023 Год назад
Really great video, thank you. Very clear, detailed and last but not least: usefull
@Runegar573
@Runegar573 Год назад
7:30 How does one sign up for MailHop? Looks like their website is just a page stating there's no website. 😅
@DesignsbyBlanc
@DesignsbyBlanc Год назад
TOM IS BACK WITH THE GOODS!
@tbjers
@tbjers Год назад
Thank you for making this video. I know we all copy and paste at times for expediency. However, to recommend that users do this, in a video, may enforce dangerous behaviors. Should people just have common sense and read the commands before they paste them? Yes, of course. But, hey, that's what we have disclaimers for. "If you feel confident in my instructions, and you are running this in a development environment, you can go ahead and copy and paste these commands into your terminal." Obviously, if your hat is really, really dark, making people dumber is obviously a worthwhile goal.
@mode4480
@mode4480 Год назад
Having multiple issues with docker compose erroring on the depends_on section of the YAML, first error is needs to be an array and then values need to be a string, any ideas ?
@johnthoithi5052
@johnthoithi5052 9 месяцев назад
my exact problem ... did you manage to sort the array thing?
@clomok
@clomok Год назад
Great video! I would love to see a comparison of Graylog and ELK stack.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
I don't think ELK Stack is not open source anymore and I don't use it so not likely to happen.
@peturdimitrov9304
@peturdimitrov9304 10 месяцев назад
Hello Tom! I managed to setup this just like you. I use version 5.1. Is there a guide or is there a way you can help to setup the SSL certs so I can use a https?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 10 месяцев назад
I have a video on HAProxy which is how I use it, but any reverse proxy should be fine.
@peturdimitrov9304
@peturdimitrov9304 10 месяцев назад
Thank you kind sir!@@LAWRENCESYSTEMS
@rpungello
@rpungello Год назад
One thing I cannot for the life of me figure out is how to use NFS to store the actual log data (opensearch). If you try and use docker-compose to store the data on an NFS volume, the container fails to launch as it seems the image is trying to run chown on the data storage directory, which I guess nfs doesn't allow.
@charlescc1000
@charlescc1000 10 месяцев назад
I have the exact same problem. Did you ever fix? Are you using TrueNAS to serve the NFS? I am- I believe the solution is either dataset permissions or the NFS share mapping. Have read a bunch on NFS permissions and I cannot seem to figure this out.
@rpungello
@rpungello 10 месяцев назад
@@charlescc1000I never did, no, but I didn't spend a ton of time trying as it wasn't that critical. I suspect the best approach would be to tweak the docker image so it doesn't try and fiddle with ownership/permissions.
@supernenechi
@supernenechi Год назад
Very cool video! I'll definitely be watching it! If I may make a request for another video: could you do one on Fluentbit/Fluentd? (I never know what to call it). It's always been such a headache for me to get back into the config logic once something decides to break again, but it's otherwise been working so perfectly for us! I'd love to see your take on it and see if I missed anything.
@James-xg4jr
@James-xg4jr Год назад
Finnnnnnalllly the notification I’ve been waiting for
@tundrastreaming
@tundrastreaming Год назад
I was getting some "depends_on" errors when trying to run the docker-compose I fixed it by using "docker compose" instead of "docker-compose" command
@DanteWilliams01
@DanteWilliams01 Год назад
Thank you! I was having the same problem.
@davidwhyte4439
@davidwhyte4439 Год назад
thank you much man.
@Baku-oc5fc
@Baku-oc5fc Год назад
Well done - thank you!
Год назад
I thought we should not install and use docker-compose anymore, but use the docker compose command in the newer versions of docker?
@fbifido2
@fbifido2 Год назад
@16:35 - why does graylog don't have template extractors (plus make it auto detect) for standard stuff: windows.linux-pc/laptops/servers, mac, pfsense, etc...?
@turbo2ltr
@turbo2ltr Год назад
So an index is just a way to do high level categorizing/grouping of data sets/sources?
@codencolor
@codencolor 11 месяцев назад
Saw in the latest docs that the virtual appliances is no longer available, neither able to find the OVA image. Not sure if its possible to install this in docker on a mac setup.
@Dushyantgiri
@Dushyantgiri Год назад
If we are using elastic search then what's the advantage with this tool? Why should we use it?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
I find graylog easier to manage and setup compared to Elastic
@Dushyantgiri
@Dushyantgiri Год назад
@@LAWRENCESYSTEMS thanks
@LostJediJC
@LostJediJC 8 месяцев назад
i'm trying to find a way to have it alert me when dhcp leases are given out for new MAC addresses on the network, i have this working via syslog-ng and a bash script but if i can do through the GUI in Greylog that would be great
@XtrAMassivE
@XtrAMassivE 10 месяцев назад
Can anyone tell me which one is best for log managment between Graylog, Wazuh and ELK? Mainly for Windows servers and Mikrotik routers.
@pivot3india
@pivot3india 11 месяцев назад
Does gray log provide functionality in addition to wazuh ? Or they are same.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 11 месяцев назад
Wazuh is more focused on security.
@ClaudeAlexandreRochatProfile
@ClaudeAlexandreRochatProfile 11 месяцев назад
Great job 🎉
@jobtechnologies3492
@jobtechnologies3492 Год назад
Just set it up, super easy! now who knows where I can find a json for unifi extractors?!?
@turb0t
@turb0t Год назад
This was a great tutorial, Thank you. Do you know if its possible to have Graylog record information on each of the TCP sessions from PFsense firewall, for example, how many bytes sent/received for each TCP session, and if the TCP session ended with FIN or RST ?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
Maybe with netflow, I have not tried.
@MrXankiller
@MrXankiller Год назад
I've more than 25 docker containers running on few different VMs, I'm no expert in docker but not really a newbie either But starting Graylog? I just can't do it The way they implemented the $USER is beyond my understanding Keep getting stuck at this error when Graylog is starting: ERROR org.graylog2.bootstrap.CmdLineTool - Couldn't load configuration: Properties file /usr/share/graylog/data/config/graylog.conf doesn't exist! (And yes it exist, and it is mapped correctly) I've tried to set user variables, tried to change directly the mounted directory ownership to 1100:1100 I've tried with other versions of docker-compose Tried also changing the owner to docker:docker Executed multiple times that "sudo usermod -aG docker $USER" Rebooted the server, tried other mounting points that are not in the /home directory Nothing works Sorry but the Graylog docker image is broken for me (and no I'm not using snap docker package even tho I'm running on Ubuntu Server) Thank you for the tutorial but sadly I might have to many skill issues to solve this
@gjkrisa
@gjkrisa Год назад
It’s odd I set this up and found that windows 11 default firewall blocks port 9000 so I thought it wasn’t working and then decided to try my phone and it was working except that some reason my password I placed was not working.
@perfecto25
@perfecto25 Год назад
very helpful thank you
@WoodsTech
@WoodsTech 7 месяцев назад
@Lawrencesystems Tom, Have you used the SIEM product (Graylog Security) before. I'm interested in a platform like that to help with cyber threats. Do have any other suggestions as far as an SIEM log platform?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 7 месяцев назад
We use Blumira ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-5dytu5YW0LY.htmlsi=LmRTQTgeaT-4otYk
@vladislavkalashnikov1744
@vladislavkalashnikov1744 Год назад
Hey Tom, could you make a video about zabbix as a comparison. It has pre-defined templates and triggers for the most popular systems, linux, windows, firewalls, etc. Very powerful tool. I would love to see it on your channel. It comes containerized as well.
@monkeythebob
@monkeythebob Год назад
Yesss, would love to see a containerized walkthrough of Zabbix
@josh-rx6ly
@josh-rx6ly Год назад
Is there a way to set this up over https? I want greylog itself to have the https cert.
@prashanthg6044
@prashanthg6044 Год назад
This is very good!👏
@Baku-oc5fc
@Baku-oc5fc Год назад
I may have done something wrong because messages are only hitting the very last stream/indices I created. In other words, PFsense was the first one created, and messages were hitting it. The last one I created was for a Cisco switch, and now no PfSense messages, but lots of messages to the Cisco switch. Any thoughts on this? Thanks!
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
You have a setting incorrect in the stream rule
@samueleannulli4956
@samueleannulli4956 Год назад
hi good evening, very good works...please a question?...how do yo do your prompt console??? many thanks in advance
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
github.com/lawrencesystems/dotfiles
@jeffrmontg
@jeffrmontg 4 месяца назад
Would like to see how the logs can be redirected to another mnt drive. The quick explanation did not work.
@stefanforest7582
@stefanforest7582 Год назад
Great video.
@kristiankrautwald8074
@kristiankrautwald8074 Год назад
Great Video, but why are you not dealing with IPv6? The world is 33% based IPv6 and growing. So anyone with a IPv6 extractor that work?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
I don't use IPV6
@kristiankrautwald8074
@kristiankrautwald8074 Год назад
@@LAWRENCESYSTEMSWhy not? I think your already great videos would be even more useful.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
@@kristiankrautwald8074 I just don't have a use case for it at this time
@jb5631
@jb5631 Год назад
​@@LAWRENCESYSTEMSI think your focus is wrong on this because ipv6 has many advantages and we will have to move to it anyway, so better be up to date sooner than later
@baldsealion
@baldsealion Месяц назад
@@jb5631 you forget the part where YT channels are a business
@OthmanAlikhan
@OthmanAlikhan Год назад
Thanks for the video =)
@Scxe
@Scxe 8 месяцев назад
Why would I want to configure smtp logging for graylog?
@shlomiefeldman2500
@shlomiefeldman2500 Год назад
Hey Tom, thanks for your amazing videos! Small request, would it be possible to raise the volume on your videos, I find it even with my speakers cranked to to max I still have a hard time hearing you. (If it's too loud for someone they can always reduce volume vs raising isn't always possible).
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
My volume is at where it should be for RU-vid
@gakky_sensei
@gakky_sensei Год назад
Thanks for the video for deploying graylog. It seems your demo server has 8 core 4GB memory. I know it is for demo purpose. But how can I calcurate the necessary hardware resource for certain system ?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
It depends on how much data you are sending
@JinLi0
@JinLi0 10 месяцев назад
great video
@Nostang3
@Nostang3 Год назад
Wish you would do a install version of this on scale. It seems impossible to get it to work. Everyone and their mom is using yaml and scale doesn't.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
I don't have an interest in trying to make it work with their system. If you really want it working in Scale I would run it as a VM.
@robert4049
@robert4049 Год назад
Is there any way to get UniFi Firewall logs into Graylog?
@benchymarquez2963
@benchymarquez2963 9 дней назад
Hi. Can you help mo sir how can I add router and switches in the graylog for me to monitor my network
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 9 дней назад
Graylog collects SYSLOG. Have your switches send their SYSLOG data there.
@benchymarquez2963
@benchymarquez2963 8 дней назад
@@LAWRENCESYSTEMS I didn't put specific IP yet on the syslog. May I know what is the command to show the syslog were I can input the switch ip or if there's a guide on how to add switches and router in graylog. I really need your help sir. Thanks
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 8 дней назад
@@benchymarquez2963 every router has it's own way but the goal is to have them send it to Graylog
@PowerUsr1
@PowerUsr1 Год назад
Clean install of Ubuntu 22.04. Graylog container wont start. Stays in thee 'starting' status. I then instead install graylog natively with opensearch and mongo. Runs without issue. Something wrong with the compose file maybe?
@rv112xy
@rv112xy Год назад
Same issue. I see a lot of logs running but it doesn't get up.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
As I said in the video, make sure you are not using the SNAP version of Docker.
@PowerUsr1
@PowerUsr1 Год назад
@@LAWRENCESYSTEMS I’m not. Docker is installed via apt
@rv112xy
@rv112xy Год назад
@@LAWRENCESYSTEMS I did not. Just forgot the -d behind docker-compose up.
@mistakek
@mistakek Год назад
Same here. I thought it was just me, but no, docker installed via apt, clean ubuntu 22.04 vm installed on my proxmox server.
@raf9335
@raf9335 Год назад
maybe you can compare Graylog to other open source systems?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
Like which one?
@raf9335
@raf9335 Год назад
@@LAWRENCESYSTEMS Maybe Prometheus + Grafana, Zabbix or ELK Stack
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
Zabbix is not a log server, Prometheus is not really a log server, and I don't think ELK Stack is open source anymore. Maybe I should do a video on monitoring vs logging.
@AlexKidd4Fun
@AlexKidd4Fun Год назад
@@LAWRENCESYSTEMSGrafana Loki.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
@@AlexKidd4Fun It's much more complex to configure and I don't use it so not likely I would do a video on it.
@koevoet7288
@koevoet7288 3 месяца назад
What the f, i gave my graylog vm the same static last octet as you did by coincidence, only difference is mine uses 49 as octet 3
@siddharthkaza5021
@siddharthkaza5021 Год назад
Great video! What terminal are you using? Looks awesome
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
It's on my GitHub
@ryanhall5059
@ryanhall5059 9 месяцев назад
@@LAWRENCESYSTEMS What is it under because I'm not seeing it?
@lalala987
@lalala987 Год назад
@Lawrencesystems: did you get a new t-shirt? :)
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
yup!
@boriss282
@boriss282 Год назад
is any specific reason do you using opensearch instead elasticsearch ?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
It's what they default to probably because of potential license issues
@cparker4486
@cparker4486 Год назад
How weird. I was just trying to get Graylog running in Docker on my Synology this morning.
@Battleripper
@Battleripper Год назад
BUT How do I make a cluster system with redundancy purposes
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
Follow the guide on their site go2docs.graylog.org/5-0/setting_up_graylog/multi-node_setup.html
@willblanton3120
@willblanton3120 Год назад
Tom, is it recommended to use docker compose for production?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
Yes
@willblanton3120
@willblanton3120 Год назад
@@LAWRENCESYSTEMS awesome! I’ve seem companies say “use this for testing and not production” so it’s good to hear that’s not the case here! Like you mentioned on HLS, using docker compose is an easy way to not worry about Linux distro for your apps! Lol
@threeEyedKing
@threeEyedKing 4 месяца назад
Did you get a new shirt though?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS 4 месяца назад
Yes, they did send me one!
@ehink2716
@ehink2716 Год назад
any reason why greylog instead of elastic?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
Fully open source, easier to use, and more flexible.
@mynightoff
@mynightoff Месяц назад
"docker compose up" works for me (without "-" in "docker-compose").
@JensHummelmose
@JensHummelmose Год назад
Great video - I used your compose file and i get this "mongodb exited with code 132" every time I try to run docker-compose up. I can't find any errors - It runs on proxmox in a ubuntu 22.04 LTS VM. any ideas ?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
Nope, I just built a new VM with the latest Ubuntu and could not get the same error.
@JensHummelmose
@JensHummelmose Год назад
@@LAWRENCESYSTEMS Weird - but thanks for trying - Thanks for your answer 🙂
@xbb
@xbb Год назад
You may need to pass AVX CPU extension to the VM (if your host CPU supports it). MongoDB 5+ requires it.
@JensHummelmose
@JensHummelmose Год назад
@@xbb Thanks more than a million - That was the solution - It booted up right away after that - YOU ARE A CHAMP
@HasnainReza
@HasnainReza Год назад
@@xbb how do you do that? I'm running into this issue as sell
@fordcrews3362
@fordcrews3362 Год назад
How about a video with a sidecar and windows logs?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
Eventually
@monkeythebob
@monkeythebob Год назад
@@LAWRENCESYSTEMS Looking forward to it. Been struggling to implement that for my org, and can't find a useful tutorial for implementing sidecar with Graylog containorized
@LA-MJ
@LA-MJ Год назад
What happened at 16:14?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
That's how you get the message to create an extractor from
@talishkavonzua
@talishkavonzua Год назад
Does Lawrence System have a vpn tutorial for mobile clients (including android 12 / 13)?
@severgun
@severgun Год назад
what about loki?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
More complex to configure but is still a popular solution
@mcury85
@mcury85 Год назад
Graylog here for: Syslog: pfsense, unifi, synology nas. Netflow: pfsense Works great 👍
@Stephen-wh7vl
@Stephen-wh7vl Год назад
Do a pipeline vidjayo
@sametsahin-eh3qj
@sametsahin-eh3qj Месяц назад
bro got that long ahh screen
@abbcc555
@abbcc555 Год назад
This turns painful really quick if your processor doesn't support AVX.
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
Processors have supported AVX since 2011
@abbcc555
@abbcc555 Год назад
@@LAWRENCESYSTEMS hey not everybody has the shiniest newest stuff. *cries with X5650*
@vladislavkalashnikov1744
@vladislavkalashnikov1744 Год назад
Can I attach any dashboard to greylog?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
I don't understand the question.
@minerzcollective6755
@minerzcollective6755 Год назад
First!
@HirschyKiss
@HirschyKiss Год назад
this was such a fucking mess for me. Once I got permissions all figured out, I found out that mongo 5.0+ required hardware that apperantly my box didn't have, and then I tried to figure out compatability between all three, and i just gave up, it's not worth it for something to needless for me...
@turb0t
@turb0t Год назад
Hey Hirschy, try replacing docker image "mongo:6.0.5-jammy" with "nwzz/mongo-without-avx:6.0.5-jammy" , and make sure you remove all data volumes first if you might have tried using an older version of mongo
@marcospaulo-xl3ey
@marcospaulo-xl3ey Месяц назад
@@turb0t ty for the info
@Meowbay
@Meowbay 9 месяцев назад
The snap install was a lot better though. Just sayin'. Docker is equal to useless overhead and useless complexity.
@AliG.G
@AliG.G Год назад
I don't think it's open source
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
Not sure why you think that, but their source code is available which means it's open source.
@chswin
@chswin Год назад
Seq is better…
@HasnainReza
@HasnainReza Год назад
Hi Tom, I added this to my existing docker (installed via apt) but the graylog container is not starting up. I'm getting this in the logs: com.mongodb.MongoSocketException: mongodb: Temporary failure in name resolution Caused by: java.net.UnknownHostException: mongodb: Temporary failure in name resolution 2023-05-13 15:13:58,222 INFO : org.graylog2.bootstrap.preflight.MongoDBPreflightCheck - MongoDB is not available. Retry #1 2023-05-13 15:14:00,222 INFO : org.mongodb.driver.cluster - Cluster description not yet available. Waiting for 30000 ms before timing out I've tried removing and re-deploying but no luck.
@frankfix247
@frankfix247 Год назад
What about Grafana & Prometheus? What are the differences?
@LAWRENCESYSTEMS
@LAWRENCESYSTEMS Год назад
Grafana & Prometheus are for metrics collection and not logs.
@frankfix247
@frankfix247 Год назад
@@LAWRENCESYSTEMS Thanks for clearing that out. Love your channel btw, keep up the good work!
Далее
История Hamster Kombat ⚡️ Hamster Academy
04:14
This web UI for Ansible is so damn useful!
20:07
Просмотров 481 тыс.
CrowdSec Absolute Beginners Workshop
46:57
Просмотров 10 тыс.
this Cybersecurity Platform is FREE
39:46
Просмотров 572 тыс.
you need this FREE CyberSecurity tool
32:06
Просмотров 1,2 млн