Installing And Configuring Filebeat On Centos/RHEL

Published on Author gryzliLeave a comment

Filebeat is a perfect tool for scraping your server logs and shipping them to Logstash or directly to ElasticSeearch. You will find some of my struggles with Filebeat and it’s proper configuration.   Installing Filebeat under Centos/RHEL As with all ELK products the installation process is really easy and straight forward. Filebeat could be easily… Continue reading Installing And Configuring Filebeat On Centos/RHEL

Linux Admin Daily Usage

Published on Author gryzliLeave a comment

Shell   Calculate the size of all files from a given type/extension Recently I need something for doing such calculations and end up with the following command line (found on stackexchange), which will calculate the size summary for all “*.jpg” files in “some_directory”. find some_directory/ -type f -name ‘*.jpg’ -exec du -ch {} + |… Continue reading Linux Admin Daily Usage

ElasticSearch CheatSheet

Published on Author gryzliLeave a comment

ElasticSearch Example Queries  Searching with wildcard query.   Changing the size of the search result to 100 items.  GET /filebeat-apache2-access-2019.01.10/_search { “size”:100, “query”: { “wildcard”: { “apache2.access.url” : “*CHAR(*” } } } Filter aggregations by minimum document count in the result by using min_doc_count setting. # will print aggregation buckets only if they consist of… Continue reading ElasticSearch CheatSheet

ElasticSearch Security – Installing And Configuring Search-Guard How-To

Published on Author gryzliLeave a comment

Security is one of the major “missing” things from the free ELK Stack compilation, so let’s talk about achieving it! Soon or later there will come time, when you may want some more “Secure” ElasticSearch cluster, and by “Secure” I mean some of the following : Encrypted communication between cluster nodes Encrypted communication between “Indexing… Continue reading ElasticSearch Security – Installing And Configuring Search-Guard How-To

ElasticSearch Choosing Field Mappings

Published on Author gryzliLeave a comment

If you want to spend good time with ElasticSearch you must choose very carefully your elasticsearch index field mappings. Proper field mappings are extremely important in order to be able to search properly inside your data. Keep in mind that ElasticSearch differs a lot between major versions. The current article is written for the current… Continue reading ElasticSearch Choosing Field Mappings

How ElasticSearch Works (Basic Concepts)

Published on Author gryzliLeave a comment

I’m going to skip the intro about Elasticsearch and it’s primary application (which is for search) and will go straight to the point. If you need some basic understanding of what is Elasticsearch and how to use it, I suggest you to start with the official documentation which is one of the best software documentations… Continue reading How ElasticSearch Works (Basic Concepts)

WordPress WP GDPR Compliance Privilege Escalation Exploit

Published on Author gryzliLeave a comment

Two days ago (on November 08 2018) nasty WP exploit has been identified inside the popular GDPR wordpress plugin , that leads to privilege escalation.  The plugin has more than 100 000 active installations.  All versions prior 1.4.3 (except 1.4.3) are vulnerable to the exploit.    What is the actual vulnerability ?  More information about… Continue reading WordPress WP GDPR Compliance Privilege Escalation Exploit

Decoding \x{ZZZZ} utf8 strings inside perl

Published on Author gryzliLeave a comment

We have some cPanel accounts with Cyrillic language set to default, which makes cPanel to return escaped utf8 messages while you operating with the API.  One of the example messages I was getting , looked like this : \x{437}\x{430}\x{43f}\x{438}\x{441} \x{437}\x{430} \x{434}\x{43e}\x{43c}\x{435}\x{439}\x{43d} \x{201c} some-user-domain.com \x{201d} \x{432}\x{435}\x{447}\x{435} \x{441}\x{44a}\x{449}\x{435} \x{441}\x{442}\x{432}\x{443}\x{432}\x{430}. which is not very eye-friendly.   Using simple… Continue reading Decoding \x{ZZZZ} utf8 strings inside perl

Kibana Installation Under Centos / RHEL

Published on Author gryzliLeave a comment

Kibana is part of the famous ELK stack (ElasticSearch , Logstash , Kibana) and is best used for Vizualization and Interaction with your ES cluster.   When installing Kibana, it is good to make sure that your Kibana version is coresponding to your ES version. For example if you have installed ES 6.X , it… Continue reading Kibana Installation Under Centos / RHEL

Elasticsearch Installation How-To (Centos 7)

Published on Author gryzliLeave a comment

Elasticsearch install is pretty straight forward (also making cluster of elastic nodes).The following howto is about installing elasticsearch 6.x, which is the current latest version. It is good to know some basic concepts of ElasticSearch before using it.  I’m not going to talk about the hardware requirements, because they strongly depend on the setup and… Continue reading Elasticsearch Installation How-To (Centos 7)