#4 How To Send Suricata Alerts To Elastic SIEM | Kali Purple SOC In A Box Lab Series #4

Поделиться
HTML-код
  • Опубликовано: 21 авг 2024
  • We will ship suricata IDS alerts from opnsense firewall to elastic siem, then create graphs and maps of the alert traffic. A fun lab, especially for those interested in learning ethical hacking and purple teaming.
    Watch the full series: • How To Install Kali Pu...
    Resources:
    Read kali purple wiki: gitlab.com/kal... Connect and Direct Message me on Linkedin: / howard-mukanda-24503144

Комментарии • 25

  • @nump9768
    @nump9768 2 месяца назад +4

    For those of you who may be coming back to this video a year later - when you get to the part of installing filebeat - make sure you are in filebeat7 directory. Theres an issue with filebeat8 now that will not allow you past the module list command @10:33
    Downgrading to 7 allowed me to progress past this part and continue the setup.
    Also if you get an error with filebeat make install - try rebooting your opnsense - had to do both times when i installed 8 then eventually downgraded to 7.
    Cheers!

  • @Unhacker
    @Unhacker 7 месяцев назад

    Good series dude, nice work. \m/

  • @Braddeman
    @Braddeman Год назад +1

    Should of just used fleet to deploy. Set it up in two seconds. Good to know how to manually do it though. And easy way to deploy suricata is use ids tower free version. Easy to then manage rules as well. I have an ET pro rule set that is also easily deployed with ids tower as well.

  • @omurcantatar4359
    @omurcantatar4359 Год назад +3

    Hi, thanks for all videos. Since I did not set HTTPS for Kibana, I proceeded by setting the host value in the filebeat.yml file to HTTP. I completed the steps without any problems. But I want to set HTTPS for Kibana. Can you share the documentation or link for the HTTPS setting in Kibana?

    • @nump9768
      @nump9768 2 месяца назад

      I know im a bit late but i figured I'd post what worked for me - When you get to the step about setting up HTTPS make sure you hit enter through all the prompts and key the default names for the ca and keys. After adding those to your kibana.yml you need to restart the kibana service for HTTPS to take effect - fun fact this took me hours of troubleshooting to figure out.

    • @M3STERL3G3ND
      @M3STERL3G3ND 5 дней назад

      @@nump9768 Can you help-me? i feel that i lost something on OPNsense how we can install the filebeat if doesn't has a version of him that freebsd support? its only trough the kali purple?

  • @raulmoncada6757
    @raulmoncada6757 2 месяца назад

    Hi. I have one question. Is opnsense mandatory to send the logs? or I just could configure mi NIC in promiscous mode?
    Thank you

  • @boomerjrtv1268
    @boomerjrtv1268 6 месяцев назад +1

    I did not get the install prompt where you did for filebeat... I noticed you skipped some of the video. what did you do?

    • @Alpanama
      @Alpanama 3 месяца назад

      Based on what I've seen, this guy solved the issue by "downgrading" to a 8.5.3 version (ruclips.net/video/b88mnr0WsLc/видео.html). How to do that?

  • @ken6197
    @ken6197 Год назад +1

    Are we need to set up Logstash to complete ELK stash of this box

    • @ITSecurityLabs
      @ITSecurityLabs  Год назад +1

      No, the default elastic filebeat parser is sufficient for this setup

  • @maumotec2345
    @maumotec2345 Месяц назад

    How can I downgrade beats from 8.8.2 to a previous version? I went through a lot of websites but nothing clear to be honest.
    I installed beats7 but was not able to make the dashboards work

  • @alexandruionita99
    @alexandruionita99 7 месяцев назад

    Hi, thanks for all videos with kali purple! I have a problem when I execute 'filebeat modules list', I got this error: "Error initializing beat: failed to get host information: unimplemented". How can I solve that?

    • @bhaskarreddy7197
      @bhaskarreddy7197 6 месяцев назад

      I'm also facing same issue, please need a solution for this...

    • @dayones4596
      @dayones4596 5 месяцев назад +1

      @@bhaskarreddy7197 bit late, but you can make install sysutils/beats7 instead of beats8. beats 8.8.2 is the one that's installed and facing the issue. You can also try installing the version he's using here which is 8.6 (albeit another way)

  • @aviwemusa6109
    @aviwemusa6109 Год назад +2

    Can you also deploy TheHive for Incident Response?

    • @ITSecurityLabs
      @ITSecurityLabs  Год назад +2

      That sounds like a great idea for this SOC

    • @ITSecurityLabs
      @ITSecurityLabs  Год назад +2

      We will get it done

    • @aviwemusa6109
      @aviwemusa6109 Год назад

      @@ITSecurityLabs Thank you! 😁

    • @EliteSoulja360
      @EliteSoulja360 Год назад

      Will be keen to see this deployed. Thank you for the videos sir!

    • @aaron8814
      @aaron8814 Год назад

      @@ITSecurityLabs waiting for you !

  • @user-km2iw8vv6l
    @user-km2iw8vv6l Год назад

    any idea how to fix this error, i have tried everything,
    go tool dist: unexpected new file in $GOROOT/bin: go-go-tmp-umask
    *** Error code 2
    Stop.
    make[1]: stopped in /usr/ports/lang/go120
    *** Error code 1
    Stop.
    make: stopped in /usr/ports/sysutils/beats8