Suricata and Zeek IDS with ELK on Ubuntu 20.10

Discussion in 'HOWTO-Related Questions' started by Miguel, Mar 11, 2021.

  1. Miguel

    Miguel New Member HowtoForge Supporter

    Post here any remarks or questions related to this how-to.
     
  2. adelia

    adelia New Member

    Hi Miguel, thank you for your thread, it will be very helpful for me in an important task. I would like to ask, can ELK (Elasticsearch, Logstash, Kibana) be installed on a different operating system than Zeek and Suricata? And what about installing Filebeat, should it be installed on the operating system with IDS or the one with ELK? Thanks a lot
     
  3. Miguel

    Miguel New Member HowtoForge Supporter

    Elasticsearch you can install multiple instances in order to search faster.Logstash and Kibana only one instance. All can be on different machines and OS (Linux is faster than Windows).

    On each instance that you are running Suricata/Zeek, you also have to install filebeat to get the logfiles in Logstash.
     

Share This Page