I am struggling to set up visualisation for Zeek (Bro) logs with Kibana. The Zeek module included with filebeat apparently comes with a sample dashboard seen here. I am struggling to see the sample dashboard and setting up a visualisation for the conn.log from Zeek. I can see there is an index created using the configurations of filebeat:
Can you tell if your difficulty is with filebeat or kibana? You say you can see an index created, does that mean that the zeek logs are being indexed in elasticsearch, but you don't see the dashboard? Or are you unsure if the logs are being indexed at all?
I can see index on ES and indeed in Kibana and I could create an index pattern and discover the documents. But no default dashboard on Kibana. I assume its a filebeat configuration?. I am using docker so it would be easier for me to configure through filebeat.yml if there is a setting I can apply.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.