https://www.linkedin.com/pulse/cisco-sy ... 9260695552
http://blogs.cisco.com/security/step-by ... -analytics
http://www.gregmefford.com/blog/2014/09 ... -logstash/
Code: Select all
tail -n50 /var/log/logstash/logstash.logCode: Select all
{:timestamp=>"2016-06-30T10:54:36.072000-0700", :message=>"syslog listener died", :protocol=>:tcp, :address=>"0.0.0.0:5544", :exception=>#<Errno::EADDRINUSE: Address already in use - bind - Address already in use>
Code: Select all
tcp {
port => 5544
type => syslog
}
udp {
port => 5544
type => syslog
}
Code: Select all
if [type] == "syslog" {
grok {
match => { "message" => "<%{POSINT:syslog_pri}>%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
}
}