Hi All
We have centralize logging server setup across network.
All the devices of Cisco or other devices send logs to SYSLOG-NG Server. they store in based on the IP and date and time as in folder.
Now i would like to take that date and create a easy dashboard and alert system.
I am thinking to 2 options here.
SYSLOG-NG --File-beat--Logstasg-ElasticSearch-Kibana 
SYSLOG-NG --Logstasg-ElasticSearch-Kibana 
 
What is your suggestion ?
Thank you 
R!
             
            
               
               
               
            
            
           
          
            
              
                czanik  
                (Peter Czanik)
               
              
                  
                    April 15, 2017,  6:30pm
                   
                   
              2 
               
             
            
            
               
               
               
            
            
           
          
            
            
              Thank you, i have seen that post already,
As per my understanding,  new syslog-ng can directly send the logs to elasticsearch.
But i am looking some normalization before sending to elasticsearch, due to heavy traffic from ASA or Checkpoint.
So i was thinking to use use logstash between, make sense ?
R!
             
            
               
               
               
            
            
           
          
            
              
                system  
                (system)
                  Closed 
               
              
                  
                    May 13, 2017,  7:24pm
                   
                   
              4 
               
             
            
              This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.