COMO INSTALAR SERVIDOR GRAYLOG DEBIAN 11 E INTEGRAR COM MIKROTIK E HUAWEI

 VAMOS APRENDE O PASSO A PASSO DE TUDO!

 

sudo apt install wget curl gnupg software-properties-common apt-transport-https ca-certificates lsb-release pwgen


Install Elasticsearch 7:


curl  -fsSL https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo gpg --dearmor -o /etc/apt/trusted.gpg.d/elastic.gpg

echo "deb https://artifacts.elastic.co/packages/oss-7.x/apt stable main" | sudo tee  /etc/apt/sources.list.d/elastic-7.x.list


sudo apt update

sudo apt install elasticsearch-oss



nano /etc/elasticsearch/elasticsearch.yml 



cluster.name: graylog

action.auto_create_index: false  


systemctl enable --now elasticsearch



Install MongoDB:


curl -fsSL https://www.mongodb.org/static/pgp/server-6.0.asc|sudo gpg --dearmor -o /etc/apt/trusted.gpg.d/mongodb-6.gpg

echo "deb http://repo.mongodb.org/apt/debian bullseye/mongodb-org/6.0 main" | sudo tee /etc/apt/sources.list.d/mongodb-org-6.0.list

sudo apt update


sudo apt install mongodb-org


systemctl enable --now mongod



Install Java JDK 17:


sudo apt install openjdk-17-jdk



Install graylog:


wget https://packages.graylog2.org/repo/packages/graylog-5.0-repository_latest.deb

sudo dpkg -i graylog-5.0-repository_latest.deb

sudo apt update && sudo apt install graylog-server


pwgen -N 1 -s 96

password_secret=


echo -n coloquesuasenha | shasum -a 256

root_password_sha2 = 


nano /etc/graylog/server/server.conf


vamos fazer 3 configuração basicas

password_secret = 

root_password_sha2 = 

descomente o http e coloque o ip da vm 

http_bind_address = 192.168.100.5:9000


reinicie e faça um teste de log

# systemctl restart elasticsearch graylog-server.service



# systemctl restart elasticsearch graylog-server mongod

tail /var/log/graylog-server/server.log


para acessa coloque o ip ,369do graylog com a porta 9000

ex: 192.168.100.2:9000


Configure seu agora em seus roteadores



mikrotik:


/system logging action
 add name=RouterLog remote=250.250.250.2 remote-port=65014 target=remote
 
 /system logging
 add action=RouterLog topics=info
 add action=RouterLog topics=warning
 add action=RouterLog topics=critical
 add action=RouterLog topics=error


Configurando syslog no Huawei


info-center channel 6 name logserver
 info-center source default channel 6 log level informational
 info-center loghost source LoopBack0
 info-center loghost 250.250.250.2 channel 6 facility local2 port 65014




dentro do graylog faça o seguinte:









Postar um comentário

0 Comentários