Suricata and Zeek IDS with ELK on Ubuntu 20.10

Discussion started by Miguel, Mar 11, 2021.

  Miguel

    Miguel

    Post here any remarks or questions related to this how-to.
  adelia

    adelia

    Hi Miguel, thank you for your thread, it will be very helpful for me in an important task. I would like to ask, can ELK (Elasticsearch, Logstash, Kibana) be installed on a different operating system than Zeek and Suricata? And what about installing Filebeat, should it be installed on the operating system with IDS or the one with ELK? Thanks a lot
  Miguel

    Miguel

    Elasticsearch you can install multiple instances in order to search faster.Logstash and Kibana only one instance. All can be on different machines and OS (Linux is faster than Windows).

    On each instance that you are running Suricata/Zeek, you also have to install filebeat to get the logfiles in Logstash.

