I am absolutely new to the ELK-Stack, but as described in my other thread I have an ELK-Stack running since yesterday and absolutely flashed what is possible with this.
Since yesterday I also send my TMG access log files (w3c) per filebeat to logstash and have them now visible in Kibana.
I already heard and read about how to grok such log files, but I don't know how start. I had one try yesterday, but nothing happened.
My log looks like this:
10.10.10.10 domain\user Microsoft Office/15.0 (Windows NT 6.3; Microsoft Outlook 15.0.4849; Pro) 2016-09-21 23:51:45 TMG - subdomain.domain.com 172.16.0.1 443 47 883 4446 https POST http://subdomain.domain.com/autodiscover/autodiscover.xml text/xml; charset=utf-8 Inet 200 Outlook Anywhere Req ID: 0a61611c; Compression: client=No, server=No, compress rate=0% decompress rate=0% ; FBA cookie: exists=no, valid=no, updated=yes, logged off=no, client type=unknown, user activity=yes Perimeter Local Host 0x600 Allowed - Allowed - - - - - - 0 - 0 - 172.16.100.1 - Web Proxy subdomain.domain.com 41461 -
Could you explain me how it works?
I would also like to know how I can install the GeoIP plugin and how to use that.
Thank you very much!