Skip to content

Logstash configuration files for analyzing various types of logs

License

Notifications You must be signed in to change notification settings

timmolter/logstash-dfir

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

64 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

logstash-dfir

Logstash configuration files for analyzing various types of logs. These configuration files are provided to analyze various types of log files using logstash, elasticsearch, and kibana.

Whether you are running a full-blown setup of ElasticSearch, Kibana, and log shippers, or a single instance for rapid analysis, these configuration files will help you quickly parse various log files found on system images.

Logstash

Logstash Website

Other Resources

sysforensics GitHub

Related Posts

I'll take some Elasticsearch/Kibana with my Plaso (Windows edition)

Finding the Needle in the Haystack with ELK

Rapid Log Analysis

Do you even Bro, bro?

Utilizing Dictionaries with Logstash

Changelog

07 Jan 2015 - Uploaded logstash dictionaries for HTTP, FTP, and Bro IDS conn log status codes

04 Sep 2014 - Uploaded Bro IDS logs; thanks to team at http://www.appliednsm.com for laying the groundwork

02 Mar 2014 - Added log2timeline logstash config

01 Mar 2014 - Added apache-combined logstash config

22 Feb 2014 - Repository created; uploaded apache-common logstash config.

About

Logstash configuration files for analyzing various types of logs

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published