Issue: when loading a fresh elk stack install into a Ubuntu 16.04 vagrant, the Kibana app will not show the Overview tab. (see screenshot). This is a single server architecture without filebeat. Also the Manager/Agent tabs of Kibana seem to work just fine, with everything showing green.
Full url: http://192.168.34.2/app/wazuh#/overview?_g=(refreshInterval:(display:Off,pause:!f,value:0),time:(from:now-1d,mode:quick,to:now))&view=panels&tab=pci&_a=(columns:!(_source),index:'wazuh-alerts-*',query:'_exists_:rule.pci_dss%20AND%20manager.name:%20default-ubuntu-1604',sort:!('@timestamp',desc),uiState:(vis:(legendOpen:!f,params:(sort:(columnIndex:!n,direction:!n)))))
Other information:
elasticsearch: 5.6.0
logstash: 1:5.6.0-1
kibana: 5.6.0
java: oracle 1.8.0_131
wazuhapp: wazuhapp-2.1.0_5.6.0.zip
wazuh-manager: 2.1.0-1xenial
wazuh-api: 2.1.0-1xenial
It might also help that I am running kibana through a reverse nginx proxy. Here is the nginx config:
upstream kibana {
server 127.0.0.1:5601;
}
server {
listen *:80;
server_name 192.168.34.2;
location / {
proxy_pass http://kibana;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_connect_timeout 180;
proxy_send_timeout 180;
proxy_read_timeout 180;
}
}
My kibana.yml file:
# Kibana is served by a back end server. This setting specifies the port to use.
server.port: 5601
# Specifies the address to which the Kibana server will bind. IP addresses and host names are both valid values.
# The default is 'localhost', which usually means remote machines will not be able to connect.
# To allow connections from remote users, set this parameter to a non-loopback address.
server.host: "0.0.0.0"
# The Kibana server's name. This is used for display purposes.
server.name: "192.168.34.2"
# Enables you specify a file where Kibana stores log output.
logging.dest: '/var/log/kibana.log'
Logstash/ES Config template:
# Wazuh - Logstash configuration file
## Remote Wazuh Manager - Filebeat input (only for multiple server hosts)
# input {
# beats {
# port => 5000
# codec => "json_lines"
# ssl => true
# ssl_certificate => "/etc/logstash/logstash.crt"
# ssl_key => "/etc/logstash/logstash.key"
# }
# }
## Local Wazuh Manager - JSON file input
input {
file {
type => "wazuh-alerts"
path => "/var/ossec/logs/alerts/alerts.json"
codec => "json"
}
}
filter {
#geoip {
# source => "srcip"
# target => "GeoLocation"
# fields => ["city_name", "continent_code", "country_code2", "country_name", "region_name", "location"]
#}
date {
match => ["timestamp", "ISO8601"]
target => "@timestamp"
}
mutate {
remove_field => [ "timestamp", "beat", "fields", "input_type", "tags", "count", "@version", "log", "offset", "type"]
}
}
output {
elasticsearch {
hosts => ["localhost:9200"]
index => "wazuh-alerts-%{+YYYY.MM.dd}"
document_type => "wazuh"
template => "/etc/logstash/wazuh-elastic5-template.json"
# template => "/etc/logstash/wazuh-elastic2-template.json"
template_name => "wazuh"
template_overwrite => true
}
}
Elasticsearch.log:
[2017-09-14T20:30:17,561][INFO ][o.e.n.Node ] [] initializing ...
[2017-09-14T20:30:18,458][INFO ][o.e.e.NodeEnvironment ] [CpJRxBm] using [1] data paths, mounts [[/ (/dev/mapper/vagrant--vg-root)]], net usable_space [32.7gb], net total_space [37.7gb], spins? [possibly], types [ext4]
[2017-09-14T20:30:18,480][INFO ][o.e.e.NodeEnvironment ] [CpJRxBm] heap size [1.9gb], compressed ordinary object pointers [true]
[2017-09-14T20:30:18,482][INFO ][o.e.n.Node ] node name [CpJRxBm] derived from node ID [CpJRxBm1RLmA0xzfhEg8kA]; set [node.name] to override
[2017-09-14T20:30:18,482][INFO ][o.e.n.Node ] version[5.6.0], pid[20972], build[781a835/2017-09-07T03:09:58.087Z], OS[Linux/4.4.0-75-generic/amd64], JVM[Oracle Corporation/Java HotSpot(TM) 64-Bit Server VM/1.8.0_131/25.131-b11]
[2017-09-14T20:30:18,487][INFO ][o.e.n.Node ] JVM arguments [-Xms2g, -Xmx2g, -XX:+UseConcMarkSweepGC, -XX:CMSInitiatingOccupancyFraction=75, -XX:+UseCMSInitiatingOccupancyOnly, -XX:+AlwaysPreTouch, -Xss1m, -Djava.awt.headless=true, -Dfile.encoding=UTF-8, -Djna.nosys=true, -Djdk.io.permissionsUseCanonicalPath=true, -Dio.netty.noUnsafe=true, -Dio.netty.noKeySetOptimization=true, -Dio.netty.recycler.maxCapacityPerThread=0, -Dlog4j.shutdownHookEnabled=false, -Dlog4j2.disable.jmx=true, -Dlog4j.skipJansi=true, -XX:+HeapDumpOnOutOfMemoryError, -Des.path.home=/usr/share/elasticsearch]
[2017-09-14T20:30:26,105][INFO ][o.e.p.PluginsService ] [CpJRxBm] loaded module [aggs-matrix-stats]
[2017-09-14T20:30:26,105][INFO ][o.e.p.PluginsService ] [CpJRxBm] loaded module [ingest-common]
[2017-09-14T20:30:26,105][INFO ][o.e.p.PluginsService ] [CpJRxBm] loaded module [lang-expression]
[2017-09-14T20:30:26,105][INFO ][o.e.p.PluginsService ] [CpJRxBm] loaded module [lang-groovy]
[2017-09-14T20:30:26,105][INFO ][o.e.p.PluginsService ] [CpJRxBm] loaded module [lang-mustache]
[2017-09-14T20:30:26,105][INFO ][o.e.p.PluginsService ] [CpJRxBm] loaded module [lang-painless]
[2017-09-14T20:30:26,105][INFO ][o.e.p.PluginsService ] [CpJRxBm] loaded module [parent-join]
[2017-09-14T20:30:26,105][INFO ][o.e.p.PluginsService ] [CpJRxBm] loaded module [percolator]
[2017-09-14T20:30:26,106][INFO ][o.e.p.PluginsService ] [CpJRxBm] loaded module [reindex]
[2017-09-14T20:30:26,107][INFO ][o.e.p.PluginsService ] [CpJRxBm] loaded module [transport-netty3]
[2017-09-14T20:30:26,107][INFO ][o.e.p.PluginsService ] [CpJRxBm] loaded module [transport-netty4]
[2017-09-14T20:30:26,108][INFO ][o.e.p.PluginsService ] [CpJRxBm] no plugins loaded
[2017-09-14T20:30:38,559][INFO ][o.e.d.DiscoveryModule ] [CpJRxBm] using discovery type [zen]
[2017-09-14T20:30:42,400][INFO ][o.e.n.Node ] initialized
[2017-09-14T20:30:42,400][INFO ][o.e.n.Node ] [CpJRxBm] starting ...
[2017-09-14T20:30:43,723][INFO ][o.e.t.TransportService ] [CpJRxBm] publish_address {127.0.0.1:9300}, bound_addresses {[::1]:9300}, {127.0.0.1:9300}
[2017-09-14T20:30:47,128][INFO ][o.e.c.s.ClusterService ] [CpJRxBm] new_master {CpJRxBm}{CpJRxBm1RLmA0xzfhEg8kA}{wzb0E6anQESOP5HPnoTRrw}{127.0.0.1}{127.0.0.1:9300}, reason: zen-disco-elected-as-master ([0] nodes joined)
[2017-09-14T20:30:47,311][INFO ][o.e.h.n.Netty4HttpServerTransport] [CpJRxBm] publish_address {127.0.0.1:9200}, bound_addresses {[::1]:9200}, {127.0.0.1:9200}
[2017-09-14T20:30:47,315][INFO ][o.e.n.Node ] [CpJRxBm] started
[2017-09-14T20:30:47,468][INFO ][o.e.g.GatewayService ] [CpJRxBm] recovered [0] indices into cluster_state
[2017-09-14T20:30:55,516][INFO ][o.e.c.m.MetaDataCreateIndexService] [CpJRxBm] [.kibana] creating index, cause [api], templates [], shards [1]/[1], mappings [_default_, index-pattern, server, visualization, search, timelion-sheet, config, dashboard, url]
[2017-09-14T20:30:57,356][INFO ][o.e.c.m.MetaDataCreateIndexService] [CpJRxBm] [wazuh-monitoring-2017.09.14] creating index, cause [api], templates [wazuh], shards [5]/[1], mappings [agent, wazuh]
[2017-09-14T20:30:57,475][INFO ][o.e.m.j.JvmGcMonitorService] [CpJRxBm] [gc][15] overhead, spent [265ms] collecting in the last [1s]
[2017-09-14T20:30:58,510][INFO ][o.e.c.m.MetaDataCreateIndexService] [CpJRxBm] [wazuh-alerts-2017.09.14] creating index, cause [auto(bulk api)], templates [wazuh], shards [1]/[0], mappings [agent, wazuh]
[2017-09-14T20:30:58,818][INFO ][o.e.c.m.MetaDataCreateIndexService] [CpJRxBm] [.wazuh] creating index, cause [auto(bulk api)], templates [], shards [5]/[1], mappings []
[2017-09-14T20:31:01,634][INFO ][o.e.c.m.MetaDataMappingService] [CpJRxBm] [wazuh-alerts-2017.09.14/jx6cTv75ReSgv43aBgFYMw] update_mapping [wazuh]
[2017-09-14T20:31:01,869][INFO ][o.e.c.m.MetaDataMappingService] [CpJRxBm] [.wazuh/_u8pHubhS6OFWy4Wh10QYw] create_mapping [wazuh-setup]
[2017-09-14T20:31:02,190][INFO ][o.e.c.m.MetaDataMappingService] [CpJRxBm] [.kibana/6ckdqrHbSt6u23MFWAf4rQ] update_mapping [config]
[2017-09-14T20:32:19,753][INFO ][o.e.c.m.MetaDataMappingService] [CpJRxBm] [.wazuh/_u8pHubhS6OFWy4Wh10QYw] create_mapping [wazuh-configuration]
[2017-09-14T20:32:20,259][INFO ][o.e.c.m.MetaDataMappingService] [CpJRxBm] [wazuh-monitoring-2017.09.14/2oYe42tLTkakS77uWDMLDw] update_mapping [agent]
Kibana startup log:
{"type":"log","@timestamp":"2017-09-14T20:30:19Z","tags":["status","plugin:[email protected]","info"],"pid":21150,"state":"green","message":"Status changed from uninitialized to green - Ready","prevState":"uninitialized","prevMsg":"uninitialized"}
{"type":"log","@timestamp":"2017-09-14T20:30:19Z","tags":["status","plugin:[email protected]","info"],"pid":21150,"state":"yellow","message":"Status changed from uninitialized to yellow - Waiting for Elasticsearch","prevState":"uninitialized","prevMsg":"uninitialized"}
{"type":"log","@timestamp":"2017-09-14T20:30:19Z","tags":["error","elasticsearch","admin"],"pid":21150,"message":"Request error, retrying\nHEAD http://localhost:9200/ => connect ECONNREFUSED 127.0.0.1:9200"}
{"type":"log","@timestamp":"2017-09-14T20:30:23Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:23Z","tags":["error","elasticsearch","data"],"pid":21150,"message":"Request error, retrying\nHEAD http://localhost:9200/.kibana/config/5.6.0 => connect ECONNREFUSED 127.0.0.1:9200"}
{"type":"log","@timestamp":"2017-09-14T20:30:23Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:23Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:23Z","tags":["status","plugin:[email protected]","error"],"pid":21150,"state":"red","message":"Status changed from yellow to red - Request Timeout after 3000ms","prevState":"yellow","prevMsg":"Waiting for Elasticsearch"}
{"type":"log","@timestamp":"2017-09-14T20:30:23Z","tags":["status","plugin:[email protected]","info"],"pid":21150,"state":"green","message":"Status changed from uninitialized to green - Ready","prevState":"uninitialized","prevMsg":"uninitialized"}
{"type":"log","@timestamp":"2017-09-14T20:30:23Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Waiting Elasticsearch to be up..."}
{"type":"log","@timestamp":"2017-09-14T20:30:23Z","tags":["warning","elasticsearch","data"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:23Z","tags":["warning","elasticsearch","data"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:23Z","tags":["status","plugin:[email protected]","info"],"pid":21150,"state":"green","message":"Status changed from uninitialized to green - Ready","prevState":"uninitialized","prevMsg":"uninitialized"}
{"type":"log","@timestamp":"2017-09-14T20:30:23Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Waiting index \".kibana\" to be created and prepared...."}
{"type":"log","@timestamp":"2017-09-14T20:30:23Z","tags":["status","plugin:[email protected]","info"],"pid":21150,"state":"green","message":"Status changed from uninitialized to green - Ready","prevState":"uninitialized","prevMsg":"uninitialized"}
{"type":"log","@timestamp":"2017-09-14T20:30:24Z","tags":["status","plugin:[email protected]","info"],"pid":21150,"state":"green","message":"Status changed from uninitialized to green - Ready","prevState":"uninitialized","prevMsg":"uninitialized"}
{"type":"log","@timestamp":"2017-09-14T20:30:24Z","tags":["listening","info"],"pid":21150,"message":"Server running at http://0.0.0.0:5601"}
{"type":"log","@timestamp":"2017-09-14T20:30:24Z","tags":["status","ui settings","error"],"pid":21150,"state":"red","message":"Status changed from uninitialized to red - Elasticsearch plugin is red","prevState":"uninitialized","prevMsg":"uninitialized"}
{"type":"log","@timestamp":"2017-09-14T20:30:26Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:26Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:26Z","tags":["status","plugin:[email protected]","error"],"pid":21150,"state":"red","message":"Status changed from red to red - Unable to connect to Elasticsearch at http://localhost:9200.","prevState":"red","prevMsg":"Request Timeout after 3000ms"}
{"type":"log","@timestamp":"2017-09-14T20:30:26Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:26Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:26Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Waiting Elasticsearch to be up..."}
{"type":"log","@timestamp":"2017-09-14T20:30:26Z","tags":["warning","elasticsearch","data"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:26Z","tags":["warning","elasticsearch","data"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:26Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Waiting index \".kibana\" to be created and prepared...."}
{"type":"log","@timestamp":"2017-09-14T20:30:28Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:28Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:29Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:29Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:29Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Waiting Elasticsearch to be up..."}
{"type":"log","@timestamp":"2017-09-14T20:30:29Z","tags":["warning","elasticsearch","data"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:29Z","tags":["warning","elasticsearch","data"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:29Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Waiting index \".kibana\" to be created and prepared...."}
{"type":"log","@timestamp":"2017-09-14T20:30:31Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:31Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:32Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:32Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:32Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Waiting Elasticsearch to be up..."}
{"type":"log","@timestamp":"2017-09-14T20:30:32Z","tags":["warning","elasticsearch","data"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:32Z","tags":["warning","elasticsearch","data"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:32Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Waiting index \".kibana\" to be created and prepared...."}
{"type":"log","@timestamp":"2017-09-14T20:30:33Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:33Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:35Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:35Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:35Z","tags":["warning","elasticsearch","data"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:35Z","tags":["warning","elasticsearch","data"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:35Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Waiting Elasticsearch to be up..."}
{"type":"log","@timestamp":"2017-09-14T20:30:35Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Waiting index \".kibana\" to be created and prepared...."}
{"type":"log","@timestamp":"2017-09-14T20:30:36Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:36Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:38Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:38Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:38Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:38Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:38Z","tags":["warning","elasticsearch","data"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:38Z","tags":["warning","elasticsearch","data"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:38Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Waiting Elasticsearch to be up..."}
{"type":"log","@timestamp":"2017-09-14T20:30:38Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Waiting index \".kibana\" to be created and prepared...."}
{"type":"log","@timestamp":"2017-09-14T20:30:41Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:41Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:41Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:41Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:41Z","tags":["warning","elasticsearch","data"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:41Z","tags":["warning","elasticsearch","data"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:41Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Waiting Elasticsearch to be up..."}
{"type":"log","@timestamp":"2017-09-14T20:30:41Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Waiting index \".kibana\" to be created and prepared...."}
{"type":"log","@timestamp":"2017-09-14T20:30:43Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:43Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:45Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:45Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:45Z","tags":["warning","elasticsearch","data"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:45Z","tags":["warning","elasticsearch","data"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:45Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Waiting Elasticsearch to be up..."}
{"type":"log","@timestamp":"2017-09-14T20:30:45Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Waiting index \".kibana\" to be created and prepared...."}
{"type":"log","@timestamp":"2017-09-14T20:30:46Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"Unable to revive connection: http://localhost:9200/"}
{"type":"log","@timestamp":"2017-09-14T20:30:46Z","tags":["warning","elasticsearch","admin"],"pid":21150,"message":"No living connections"}
{"type":"log","@timestamp":"2017-09-14T20:30:54Z","tags":["status","plugin:[email protected]","info"],"pid":21150,"state":"yellow","message":"Status changed from red to yellow - No existing Kibana index found","prevState":"red","prevMsg":"Unable to connect to Elasticsearch at http://localhost:9200."}
{"type":"log","@timestamp":"2017-09-14T20:30:54Z","tags":["status","ui settings","info"],"pid":21150,"state":"yellow","message":"Status changed from red to yellow - Elasticsearch plugin is yellow","prevState":"red","prevMsg":"Elasticsearch plugin is red"}
{"type":"log","@timestamp":"2017-09-14T20:30:56Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Wazuh-setup document does not exist. Initializating configuration..."}
{"type":"log","@timestamp":"2017-09-14T20:30:56Z","tags":["\u001b[34mwazuh\u001b[39m","Wazuh agents monitoring","info"],"pid":21150,"message":"Creating today index..."}
{"type":"log","@timestamp":"2017-09-14T20:30:56Z","tags":["\u001b[34mwazuh\u001b[39m","Wazuh agents monitoring","info"],"pid":21150,"message":"Configuring Kibana for working with \"wazuh-monitoring-*\" index pattern..."}
{"type":"log","@timestamp":"2017-09-14T20:30:57Z","tags":["\u001b[34mwazuh\u001b[39m","Wazuh agents monitoring","info"],"pid":21150,"message":"Template installed and loaded: wazuh-monitoring-*"}
{"type":"log","@timestamp":"2017-09-14T20:30:57Z","tags":["\u001b[34mwazuh\u001b[39m","Wazuh agents monitoring","info"],"pid":21150,"message":"Inserting sample alert..."}
{"type":"log","@timestamp":"2017-09-14T20:30:57Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Template installed and loaded: wazuh-alerts-*"}
{"type":"log","@timestamp":"2017-09-14T20:30:57Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Inserting sample alert..."}
{"type":"log","@timestamp":"2017-09-14T20:30:57Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Creating index pattern: wazuh-alerts-*"}
{"type":"log","@timestamp":"2017-09-14T20:30:57Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Importing objects (Searches, visualizations and dashboards) into Elasticsearch..."}
{"type":"log","@timestamp":"2017-09-14T20:30:59Z","tags":["\u001b[34mwazuh\u001b[39m","Wazuh agents monitoring","info"],"pid":21150,"message":"Successfully initialized!"}
{"type":"log","@timestamp":"2017-09-14T20:30:59Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Created index pattern: wazuh-alerts-*"}
{"type":"log","@timestamp":"2017-09-14T20:31:01Z","tags":["status","plugin:[email protected]","info"],"pid":21150,"state":"green","message":"Status changed from yellow to green - Kibana index ready","prevState":"yellow","prevMsg":"No existing Kibana index found"}
{"type":"log","@timestamp":"2017-09-14T20:31:01Z","tags":["status","ui settings","info"],"pid":21150,"state":"green","message":"Status changed from yellow to green - Ready","prevState":"yellow","prevMsg":"Elasticsearch plugin is yellow"}
{"type":"log","@timestamp":"2017-09-14T20:31:01Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Templates, mappings, index patterns, visualizations, searches and dashboards were successfully installed. App ready to be used."}
{"type":"log","@timestamp":"2017-09-14T20:31:01Z","tags":["\u001b[34mwazuh\u001b[39m","Wazuh agents monitoring","info"],"pid":21150,"message":"Sample alert inserted"}
{"type":"log","@timestamp":"2017-09-14T20:31:01Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Sample alert inserted"}
{"type":"log","@timestamp":"2017-09-14T20:31:01Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Wazuh set up info inserted"}
{"type":"log","@timestamp":"2017-09-14T20:31:01Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Setting Kibana default values: Index pattern, time picker and metaFields..."}
{"type":"log","@timestamp":"2017-09-14T20:31:02Z","tags":["\u001b[34mwazuh\u001b[39m","initialize","info"],"pid":21150,"message":"Kibana default values set"}
Logstash logs:
[2017-09-14T20:31:05,457][INFO ][logstash.modules.scaffold] Initializing module {:module_name=>"fb_apache", :directory=>"/usr/share/logstash/modules/fb_apache/configuration"}
[2017-09-14T20:31:05,468][INFO ][logstash.modules.scaffold] Initializing module {:module_name=>"netflow", :directory=>"/usr/share/logstash/modules/netflow/configuration"}
[2017-09-14T20:31:05,497][INFO ][logstash.setting.writabledirectory] Creating directory {:setting=>"path.queue", :path=>"/var/lib/logstash/queue"}
[2017-09-14T20:31:05,498][INFO ][logstash.setting.writabledirectory] Creating directory {:setting=>"path.dead_letter_queue", :path=>"/var/lib/logstash/dead_letter_queue"}
[2017-09-14T20:31:05,585][INFO ][logstash.agent ] No persistent UUID file found. Generating new UUID {:uuid=>"9f1e2118-caf6-49e9-9d8e-d5b85751db0b", :path=>"/var/lib/logstash/uuid"}
[2017-09-14T20:31:07,642][INFO ][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=>{:removed=>[], :added=>[http://localhost:9200/]}}
[2017-09-14T20:31:07,643][INFO ][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck_url=>http://localhost:9200/, :path=>"/"}
[2017-09-14T20:31:07,798][WARN ][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=>"http://localhost:9200/"}
[2017-09-14T20:31:07,800][INFO ][logstash.outputs.elasticsearch] Using mapping template from {:path=>"/etc/logstash/wazuh-elastic5-template.json"}
[2017-09-14T20:31:07,929][INFO ][logstash.outputs.elasticsearch] Attempting to install template {:manage_template=>{"order"=>0, "template"=>"wazuh*", "settings"=>{"index.refresh_interval"=>"5s", "number_of_shards"=>1, "number_of_replicas"=>0}, "mappings"=>{"wazuh"=>{"dynamic_templates"=>[{"string_as_keyword"=>{"match_mapping_type"=>"string", "mapping"=>{"type"=>"keyword", "doc_values"=>"true"}}}], "properties"=>{"@timestamp"=>{"type"=>"date", "format"=>"dateOptionalTime"}, "@version"=>{"type"=>"text"}, "agent"=>{"properties"=>{"ip"=>{"type"=>"keyword", "doc_values"=>"true"}, "id"=>{"type"=>"keyword", "doc_values"=>"true"}, "name"=>{"type"=>"keyword", "doc_values"=>"true"}}}, "manager"=>{"properties"=>{"name"=>{"type"=>"keyword", "doc_values"=>"true"}}}, "dstuser"=>{"type"=>"keyword", "doc_values"=>"true"}, "AlertsFile"=>{"type"=>"keyword", "doc_values"=>"true"}, "full_log"=>{"type"=>"text"}, "previous_log"=>{"type"=>"text"}, "GeoLocation"=>{"properties"=>{"area_code"=>{"type"=>"long"}, "city_name"=>{"type"=>"keyword", "doc_values"=>"true"}, "continent_code"=>{"type"=>"text"}, "coordinates"=>{"type"=>"double"}, "country_code2"=>{"type"=>"text"}, "country_code3"=>{"type"=>"text"}, "country_name"=>{"type"=>"keyword", "doc_values"=>"true"}, "dma_code"=>{"type"=>"long"}, "ip"=>{"type"=>"keyword", "doc_values"=>"true"}, "latitude"=>{"type"=>"double"}, "location"=>{"type"=>"geo_point"}, "longitude"=>{"type"=>"double"}, "postal_code"=>{"type"=>"keyword"}, "real_region_name"=>{"type"=>"keyword", "doc_values"=>"true"}, "region_name"=>{"type"=>"keyword", "doc_values"=>"true"}, "timezone"=>{"type"=>"text"}}}, "host"=>{"type"=>"keyword", "doc_values"=>"true"}, "syscheck"=>{"properties"=>{"path"=>{"type"=>"keyword", "doc_values"=>"true"}, "sha1_before"=>{"type"=>"keyword", "doc_values"=>"true"}, "sha1_after"=>{"type"=>"keyword", "doc_values"=>"true"}, "uid_before"=>{"type"=>"keyword", "doc_values"=>"true"}, "uid_after"=>{"type"=>"keyword", "doc_values"=>"true"}, "gid_before"=>{"type"=>"keyword", "doc_values"=>"true"}, "gid_after"=>{"type"=>"keyword", "doc_values"=>"true"}, "perm_before"=>{"type"=>"keyword", "doc_values"=>"true"}, "perm_after"=>{"type"=>"keyword", "doc_values"=>"true"}, "md5_after"=>{"type"=>"keyword", "doc_values"=>"true"}, "md5_before"=>{"type"=>"keyword", "doc_values"=>"true"}, "gname_after"=>{"type"=>"keyword", "doc_values"=>"true"}, "gname_before"=>{"type"=>"keyword", "doc_values"=>"true"}, "inode_after"=>{"type"=>"keyword", "doc_values"=>"true"}, "inode_before"=>{"type"=>"keyword", "doc_values"=>"true"}, "mtime_after"=>{"type"=>"date", "format"=>"dateOptionalTime", "doc_values"=>"true"}, "mtime_before"=>{"type"=>"date", "format"=>"dateOptionalTime", "doc_values"=>"true"}, "uname_after"=>{"type"=>"keyword", "doc_values"=>"true"}, "uname_before"=>{"type"=>"keyword", "doc_values"=>"true"}, "size_before"=>{"type"=>"long", "doc_values"=>"true"}, "size_after"=>{"type"=>"long", "doc_values"=>"true"}, "diff"=>{"type"=>"keyword", "doc_values"=>"true"}, "event"=>{"type"=>"keyword", "doc_values"=>"true"}}}, "location"=>{"type"=>"keyword", "doc_values"=>"true"}, "message"=>{"type"=>"text"}, "offset"=>{"type"=>"keyword"}, "rule"=>{"properties"=>{"description"=>{"type"=>"keyword", "doc_values"=>"true"}, "groups"=>{"type"=>"keyword", "doc_values"=>"true"}, "level"=>{"type"=>"long", "doc_values"=>"true"}, "id"=>{"type"=>"keyword", "doc_values"=>"true"}, "cve"=>{"type"=>"keyword", "doc_values"=>"true"}, "info"=>{"type"=>"keyword", "doc_values"=>"true"}, "frequency"=>{"type"=>"long", "doc_values"=>"true"}, "firedtimes"=>{"type"=>"long", "doc_values"=>"true"}, "cis"=>{"type"=>"keyword", "doc_values"=>"true"}, "pci_dss"=>{"type"=>"keyword", "doc_values"=>"true"}}}, "decoder"=>{"properties"=>{"parent"=>{"type"=>"keyword", "doc_values"=>"true"}, "name"=>{"type"=>"keyword", "doc_values"=>"true"}, "ftscomment"=>{"type"=>"keyword", "doc_values"=>"true"}, "fts"=>{"type"=>"long", "doc_values"=>"true"}, "accumulate"=>{"type"=>"long", "doc_values"=>"true"}}}, "srcip"=>{"type"=>"keyword", "doc_values"=>"true"}, "protocol"=>{"type"=>"keyword", "doc_values"=>"true"}, "action"=>{"type"=>"keyword", "doc_values"=>"true"}, "dstip"=>{"type"=>"keyword", "doc_values"=>"true"}, "dstport"=>{"type"=>"keyword", "doc_values"=>"true"}, "srcuser"=>{"type"=>"keyword", "doc_values"=>"true"}, "program_name"=>{"type"=>"keyword", "doc_values"=>"true"}, "id"=>{"type"=>"keyword", "doc_values"=>"true"}, "status"=>{"type"=>"keyword", "doc_values"=>"true"}, "command"=>{"type"=>"keyword", "doc_values"=>"true"}, "url"=>{"type"=>"keyword", "doc_values"=>"true"}, "data"=>{"type"=>"keyword", "doc_values"=>"true"}, "system_name"=>{"type"=>"keyword", "doc_values"=>"true"}, "type"=>{"type"=>"text"}, "title"=>{"type"=>"keyword", "doc_values"=>"true"}, "oscap"=>{"properties"=>{"check.title"=>{"type"=>"keyword", "doc_values"=>"true"}, "check.id"=>{"type"=>"keyword", "doc_values"=>"true"}, "check.result"=>{"type"=>"keyword", "doc_values"=>"true"}, "check.severity"=>{"type"=>"keyword", "doc_values"=>"true"}, "check.description"=>{"type"=>"text"}, "check.rationale"=>{"type"=>"text"}, "check.references"=>{"type"=>"text"}, "check.identifiers"=>{"type"=>"text"}, "check.oval.id"=>{"type"=>"keyword", "doc_values"=>"true"}, "scan.id"=>{"type"=>"keyword", "doc_values"=>"true"}, "scan.content"=>{"type"=>"keyword", "doc_values"=>"true"}, "scan.benchmark.id"=>{"type"=>"keyword", "doc_values"=>"true"}, "scan.profile.title"=>{"type"=>"keyword", "doc_values"=>"true"}, "scan.profile.id"=>{"type"=>"keyword", "doc_values"=>"true"}, "scan.score"=>{"type"=>"double", "doc_values"=>"true"}, "scan.return_code"=>{"type"=>"long", "doc_values"=>"true"}}}, "audit"=>{"properties"=>{"type"=>{"type"=>"keyword", "doc_values"=>"true"}, "id"=>{"type"=>"keyword", "doc_values"=>"true"}, "syscall"=>{"type"=>"keyword", "doc_values"=>"true"}, "exit"=>{"type"=>"keyword", "doc_values"=>"true"}, "ppid"=>{"type"=>"keyword", "doc_values"=>"true"}, "pid"=>{"type"=>"keyword", "doc_values"=>"true"}, "auid"=>{"type"=>"keyword", "doc_values"=>"true"}, "uid"=>{"type"=>"keyword", "doc_values"=>"true"}, "gid"=>{"type"=>"keyword", "doc_values"=>"true"}, "euid"=>{"type"=>"keyword", "doc_values"=>"true"}, "suid"=>{"type"=>"keyword", "doc_values"=>"true"}, "fsuid"=>{"type"=>"keyword", "doc_values"=>"true"}, "egid"=>{"type"=>"keyword", "doc_values"=>"true"}, "sgid"=>{"type"=>"keyword", "doc_values"=>"true"}, "fsgid"=>{"type"=>"keyword", "doc_values"=>"true"}, "tty"=>{"type"=>"keyword", "doc_values"=>"true"}, "session"=>{"type"=>"keyword", "doc_values"=>"true"}, "command"=>{"type"=>"keyword", "doc_values"=>"true"}, "exe"=>{"type"=>"keyword", "doc_values"=>"true"}, "key"=>{"type"=>"keyword", "doc_values"=>"true"}, "cwd"=>{"type"=>"keyword", "doc_values"=>"true"}, "directory.name"=>{"type"=>"keyword", "doc_values"=>"true"}, "directory.inode"=>{"type"=>"keyword", "doc_values"=>"true"}, "directory.mode"=>{"type"=>"keyword", "doc_values"=>"true"}, "file.name"=>{"type"=>"keyword", "doc_values"=>"true"}, "file.inode"=>{"type"=>"keyword", "doc_values"=>"true"}, "file.mode"=>{"type"=>"keyword", "doc_values"=>"true"}, "acct"=>{"type"=>"keyword", "doc_values"=>"true"}, "dev"=>{"type"=>"keyword", "doc_values"=>"true"}, "enforcing"=>{"type"=>"keyword", "doc_values"=>"true"}, "list"=>{"type"=>"keyword", "doc_values"=>"true"}, "old-auid"=>{"type"=>"keyword", "doc_values"=>"true"}, "old-ses"=>{"type"=>"keyword", "doc_values"=>"true"}, "old_enforcing"=>{"type"=>"keyword", "doc_values"=>"true"}, "old_prom"=>{"type"=>"keyword", "doc_values"=>"true"}, "op"=>{"type"=>"keyword", "doc_values"=>"true"}, "prom"=>{"type"=>"keyword", "doc_values"=>"true"}, "res"=>{"type"=>"keyword", "doc_values"=>"true"}, "srcip"=>{"type"=>"keyword", "doc_values"=>"true"}, "subj"=>{"type"=>"keyword", "doc_values"=>"true"}, "success"=>{"type"=>"keyword", "doc_values"=>"true"}}}}}, "agent"=>{"properties"=>{"@timestamp"=>{"type"=>"date", "format"=>"dateOptionalTime"}, "status"=>{"type"=>"keyword"}, "ip"=>{"type"=>"keyword"}, "host"=>{"type"=>"keyword"}, "name"=>{"type"=>"keyword"}, "id"=>{"type"=>"keyword"}}}}}}
[2017-09-14T20:31:07,963][INFO ][logstash.outputs.elasticsearch] Installing elasticsearch template to _template/wazuh
[2017-09-14T20:31:08,153][INFO ][logstash.outputs.elasticsearch] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["//localhost:9200"]}
[2017-09-14T20:31:08,169][INFO ][logstash.pipeline ] Starting pipeline {"id"=>"main", "pipeline.workers"=>1, "pipeline.batch.size"=>125, "pipeline.batch.delay"=>5, "pipeline.max_inflight"=>125}
[2017-09-14T20:31:09,213][INFO ][logstash.pipeline ] Pipeline main started
[2017-09-14T20:31:09,448][INFO ][logstash.agent ] Successfully started Logstash API endpoint {:port=>9600}
Tail end of alerts.json
{"timestamp":"2017-09-14T20:29:58+0000","rule":{"level":7,"description":"New dpkg (Debian Package) installed.","id":"2902","firedtimes":14,"mail":false,"groups":["syslog","dpkg","config_changed"],"pci_dss":["10.6.1","10.2.7"]},"agent":{"id":"000","name":"default-ubuntu-1604"},"manager":{"name":"default-ubuntu-1604"},"full_log":"2017-09-14 20:29:58 status installed systemd:amd64 229-4ubuntu16","decoder":{"name":"windows-date-format"},"hostname":"default-ubuntu-1604","location":"/var/log/dpkg.log"}
{"timestamp":"2017-09-14T20:30:00+0000","rule":{"level":7,"description":"New dpkg (Debian Package) installed.","id":"2902","firedtimes":15,"mail":false,"groups":["syslog","dpkg","config_changed"],"pci_dss":["10.6.1","10.2.7"]},"agent":{"id":"000","name":"default-ubuntu-1604"},"manager":{"name":"default-ubuntu-1604"},"full_log":"2017-09-14 20:29:58 status installed ureadahead:amd64 0.100.0-19","decoder":{"name":"windows-date-format"},"hostname":"default-ubuntu-1604","location":"/var/log/dpkg.log"}
{"timestamp":"2017-09-14T20:30:00+0000","rule":{"level":7,"description":"New dpkg (Debian Package) installed.","id":"2902","firedtimes":16,"mail":false,"groups":["syslog","dpkg","config_changed"],"pci_dss":["10.6.1","10.2.7"]},"agent":{"id":"000","name":"default-ubuntu-1604"},"manager":{"name":"default-ubuntu-1604"},"full_log":"2017-09-14 20:29:58 status installed ufw:all 0.35-0ubuntu2","decoder":{"name":"windows-date-format"},"hostname":"default-ubuntu-1604","location":"/var/log/dpkg.log"}
ES Template:
{
"order": 0,
"template": "wazuh*",
"settings": {
"index.refresh_interval": "5s",
"number_of_shards": 1,
"number_of_replicas": 0
},
"mappings": {
"wazuh": {
"dynamic_templates": [
{
"string_as_keyword": {
"match_mapping_type": "string",
"mapping": {
"type": "keyword",
"doc_values": "true"
}
}
}
],
"properties": {
"@timestamp": {
"type": "date",
"format": "dateOptionalTime"
},
"@version": {
"type": "text"
},
"agent": {
"properties": {
"ip": {
"type": "keyword",
"doc_values": "true"
},
"id": {
"type": "keyword",
"doc_values": "true"
},
"name": {
"type": "keyword",
"doc_values": "true"
}
}
},
"manager": {
"properties": {
"name": {
"type": "keyword",
"doc_values": "true"
}
}
},
"dstuser": {
"type": "keyword",
"doc_values": "true"
},
"AlertsFile": {
"type": "keyword",
"doc_values": "true"
},
"full_log": {
"type": "text"
},
"previous_log": {
"type": "text"
},
"GeoLocation": {
"properties": {
"area_code": {
"type": "long"
},
"city_name": {
"type": "keyword",
"doc_values": "true"
},
"continent_code": {
"type": "text"
},
"coordinates": {
"type": "double"
},
"country_code2": {
"type": "text"
},
"country_code3": {
"type": "text"
},
"country_name": {
"type": "keyword",
"doc_values": "true"
},
"dma_code": {
"type": "long"
},
"ip": {
"type": "keyword",
"doc_values": "true"
},
"latitude": {
"type": "double"
},
"location": {
"type": "geo_point"
},
"longitude": {
"type": "double"
},
"postal_code": {
"type": "keyword"
},
"real_region_name": {
"type": "keyword",
"doc_values": "true"
},
"region_name": {
"type": "keyword",
"doc_values": "true"
},
"timezone": {
"type": "text"
}
}
},
"host": {
"type": "keyword",
"doc_values": "true"
},
"syscheck": {
"properties": {
"path": {
"type": "keyword",
"doc_values": "true"
},
"sha1_before": {
"type": "keyword",
"doc_values": "true"
},
"sha1_after": {
"type": "keyword",
"doc_values": "true"
},
"uid_before": {
"type": "keyword",
"doc_values": "true"
},
"uid_after": {
"type": "keyword",
"doc_values": "true"
},
"gid_before": {
"type": "keyword",
"doc_values": "true"
},
"gid_after": {
"type": "keyword",
"doc_values": "true"
},
"perm_before": {
"type": "keyword",
"doc_values": "true"
},
"perm_after": {
"type": "keyword",
"doc_values": "true"
},
"md5_after": {
"type": "keyword",
"doc_values": "true"
},
"md5_before": {
"type": "keyword",
"doc_values": "true"
},
"gname_after": {
"type": "keyword",
"doc_values": "true"
},
"gname_before": {
"type": "keyword",
"doc_values": "true"
},
"inode_after": {
"type": "keyword",
"doc_values": "true"
},
"inode_before": {
"type": "keyword",
"doc_values": "true"
},
"mtime_after": {
"type": "date",
"format": "dateOptionalTime",
"doc_values": "true"
},
"mtime_before": {
"type": "date",
"format": "dateOptionalTime",
"doc_values": "true"
},
"uname_after": {
"type": "keyword",
"doc_values": "true"
},
"uname_before": {
"type": "keyword",
"doc_values": "true"
},
"size_before": {
"type": "long",
"doc_values": "true"
},
"size_after": {
"type": "long",
"doc_values": "true"
},
"diff": {
"type": "keyword",
"doc_values": "true"
},
"event": {
"type": "keyword",
"doc_values": "true"
}
}
},
"location": {
"type": "keyword",
"doc_values": "true"
},
"message": {
"type": "text"
},
"offset": {
"type": "keyword"
},
"rule": {
"properties": {
"description": {
"type": "keyword",
"doc_values": "true"
},
"groups": {
"type": "keyword",
"doc_values": "true"
},
"level": {
"type": "long",
"doc_values": "true"
},
"id": {
"type": "keyword",
"doc_values": "true"
},
"cve": {
"type": "keyword",
"doc_values": "true"
},
"info": {
"type": "keyword",
"doc_values": "true"
},
"frequency": {
"type": "long",
"doc_values": "true"
},
"firedtimes": {
"type": "long",
"doc_values": "true"
},
"cis": {
"type": "keyword",
"doc_values": "true"
},
"pci_dss": {
"type": "keyword",
"doc_values": "true"
}
}
},
"decoder": {
"properties": {
"parent": {
"type": "keyword",
"doc_values": "true"
},
"name": {
"type": "keyword",
"doc_values": "true"
},
"ftscomment": {
"type": "keyword",
"doc_values": "true"
},
"fts": {
"type": "long",
"doc_values": "true"
},
"accumulate": {
"type": "long",
"doc_values": "true"
}
}
},
"srcip": {
"type": "keyword",
"doc_values": "true"
},
"protocol": {
"type": "keyword",
"doc_values": "true"
},
"action": {
"type": "keyword",
"doc_values": "true"
},
"dstip": {
"type": "keyword",
"doc_values": "true"
},
"dstport": {
"type": "keyword",
"doc_values": "true"
},
"srcuser": {
"type": "keyword",
"doc_values": "true"
},
"program_name": {
"type": "keyword",
"doc_values": "true"
},
"id": {
"type": "keyword",
"doc_values": "true"
},
"status": {
"type": "keyword",
"doc_values": "true"
},
"command": {
"type": "keyword",
"doc_values": "true"
},
"url": {
"type": "keyword",
"doc_values": "true"
},
"data": {
"type": "keyword",
"doc_values": "true"
},
"system_name": {
"type": "keyword",
"doc_values": "true"
},
"type": {
"type": "text"
},
"title": {
"type": "keyword",
"doc_values": "true"
},
"oscap": {
"properties": {
"check.title": {
"type": "keyword",
"doc_values": "true"
},
"check.id": {
"type": "keyword",
"doc_values": "true"
},
"check.result": {
"type": "keyword",
"doc_values": "true"
},
"check.severity": {
"type": "keyword",
"doc_values": "true"
},
"check.description": {
"type": "text"
},
"check.rationale": {
"type": "text"
},
"check.references": {
"type": "text"
},
"check.identifiers": {
"type": "text"
},
"check.oval.id": {
"type": "keyword",
"doc_values": "true"
},
"scan.id": {
"type": "keyword",
"doc_values": "true"
},
"scan.content": {
"type": "keyword",
"doc_values": "true"
},
"scan.benchmark.id": {
"type": "keyword",
"doc_values": "true"
},
"scan.profile.title": {
"type": "keyword",
"doc_values": "true"
},
"scan.profile.id": {
"type": "keyword",
"doc_values": "true"
},
"scan.score": {
"type": "double",
"doc_values": "true"
},
"scan.return_code": {
"type": "long",
"doc_values": "true"
}
}
},
"audit": {
"properties": {
"type": {
"type": "keyword",
"doc_values": "true"
},
"id": {
"type": "keyword",
"doc_values": "true"
},
"syscall": {
"type": "keyword",
"doc_values": "true"
},
"exit": {
"type": "keyword",
"doc_values": "true"
},
"ppid": {
"type": "keyword",
"doc_values": "true"
},
"pid": {
"type": "keyword",
"doc_values": "true"
},
"auid": {
"type": "keyword",
"doc_values": "true"
},
"uid": {
"type": "keyword",
"doc_values": "true"
},
"gid": {
"type": "keyword",
"doc_values": "true"
},
"euid": {
"type": "keyword",
"doc_values": "true"
},
"suid": {
"type": "keyword",
"doc_values": "true"
},
"fsuid": {
"type": "keyword",
"doc_values": "true"
},
"egid": {
"type": "keyword",
"doc_values": "true"
},
"sgid": {
"type": "keyword",
"doc_values": "true"
},
"fsgid": {
"type": "keyword",
"doc_values": "true"
},
"tty": {
"type": "keyword",
"doc_values": "true"
},
"session": {
"type": "keyword",
"doc_values": "true"
},
"command": {
"type": "keyword",
"doc_values": "true"
},
"exe": {
"type": "keyword",
"doc_values": "true"
},
"key": {
"type": "keyword",
"doc_values": "true"
},
"cwd": {
"type": "keyword",
"doc_values": "true"
},
"directory.name": {
"type": "keyword",
"doc_values": "true"
},
"directory.inode": {
"type": "keyword",
"doc_values": "true"
},
"directory.mode": {
"type": "keyword",
"doc_values": "true"
},
"file.name": {
"type": "keyword",
"doc_values": "true"
},
"file.inode": {
"type": "keyword",
"doc_values": "true"
},
"file.mode": {
"type": "keyword",
"doc_values": "true"
},
"acct": {
"type": "keyword",
"doc_values": "true"
},
"dev": {
"type": "keyword",
"doc_values": "true"
},
"enforcing": {
"type": "keyword",
"doc_values": "true"
},
"list": {
"type": "keyword",
"doc_values": "true"
},
"old-auid": {
"type": "keyword",
"doc_values": "true"
},
"old-ses": {
"type": "keyword",
"doc_values": "true"
},
"old_enforcing": {
"type": "keyword",
"doc_values": "true"
},
"old_prom": {
"type": "keyword",
"doc_values": "true"
},
"op": {
"type": "keyword",
"doc_values": "true"
},
"prom": {
"type": "keyword",
"doc_values": "true"
},
"res": {
"type": "keyword",
"doc_values": "true"
},
"srcip": {
"type": "keyword",
"doc_values": "true"
},
"subj": {
"type": "keyword",
"doc_values": "true"
},
"success": {
"type": "keyword",
"doc_values": "true"
}
}
}
}
},
"agent": {
"properties": {
"@timestamp": {
"type": "date",
"format": "dateOptionalTime"
},
"status": {
"type": "keyword"
},
"ip": {
"type": "keyword"
},
"host": {
"type": "keyword"
},
"name": {
"type": "keyword"
},
"id": {
"type": "keyword"
}
}
}
}
}