I've been at this for 2 days now. Can't seem to get any teamserver logs into Kibana. I'm sure its something simple I've overlooked, but I'm not sure where I have left to check.
Cobaltstrike is running on a Kali box out of /opt, so I've manually updated the filebeat.yml to point to /opt/cobaltstrike/logs. The box does not have a direct internet connection, so to install beats I SCPed the filebeat binary and the filebeat.service files from the install on a redirector. For installation I just used the install from RedELK.
I've tested the yaml with filebeat -c /etc/filebeat/filebeat.yml -e -d "*"
This shows the harvester checking all the correct logfiles for updates, so I'm pretty sure filebeats is working, it just doesn't seem like its showing in Kibana.
I've gone through all the debugging here: https://www.digitalocean.com/community/tutorials/how-to-troubleshoot-common-elk-stack-issues
Went through the troubleshooting steps from Part 2 of the walkthrough (https://outflank.nl/blog/2020/02/28/redelk-part-2-getting-you-up-and-running/). There are errors in the install log, including failure to add the GPG key, install apt-transport-https, install filebeat, and install rush. As mentioned before, I manually moved those binaries over since the system doesnt have internet. There are issues in logstash-plain.log, but those are DNS timeout issues on resolving addresses from redirectors. greping for rtop turned up no results. The output.logstash hosts field is set to the correct ip address, and I'm not seeing any SSL errors. There were some testing beacon logs from 2 days ago that haven't loaded, and I tested a new beacon after installing filebeats on the teamserver, and I'm not seeing any data.
Tried to go through all the rush settings / edit rush.rc, but wasn't really sure how exactly that was working, or if that had anything to do with the logs getting to Kibana.
Removing the filters for Red Team Operations on Kibana doesn't help. I'm able to get data in from the redirector, just not seeing anything from the teamserver.