- 77
- 794 355
Ali Younes
Canada
Приєднався 19 лют 2018
Hello Everyone,
My name is Ali, I am a Network Analyst. I love learning networking technologies and sharing what I learn with the IT community. I earned a couple of Cisco CCNA certificates, Fortinet NSE4, and am currently working on my CCNP studies and network automation with Python.
In this channel, I share what I learn and try to explain things that gave me a hard time so you don't struggle as much 😄
Subscribe and enjoy the learning!
My name is Ali, I am a Network Analyst. I love learning networking technologies and sharing what I learn with the IT community. I earned a couple of Cisco CCNA certificates, Fortinet NSE4, and am currently working on my CCNP studies and network automation with Python.
In this channel, I share what I learn and try to explain things that gave me a hard time so you don't struggle as much 😄
Subscribe and enjoy the learning!
Kibana Overview - Visualize and Manage Your Data
#elasticsearch #logstash #kibana #elasticsearchtutorial #fortinet #fortigate Get started with the Elastic Stack. All You Need to Get Started on the Elastic Stack: Elasticsearch, Logstash, Beats and Kibana
In this lesson, we take a look at Kibana and what we can use it for, create visualizations and dashboards, explore the main features and how to start with managing the cluster.
00:00 - Intro
00:41 - Kibana Main Features
03:35 - Create Visualizations
08:35 - Create a Dashboard
11:13 - Discover App
17:40 - Search
20:04 - Observability
23:07 - Security
25:24 - Management
29:14 - Outro
Follow me on X: x.com/ayounes9
Follow me on LinkedIn: www.linkedin.com/in/aliyounes9/
In this lesson, we take a look at Kibana and what we can use it for, create visualizations and dashboards, explore the main features and how to start with managing the cluster.
00:00 - Intro
00:41 - Kibana Main Features
03:35 - Create Visualizations
08:35 - Create a Dashboard
11:13 - Discover App
17:40 - Search
20:04 - Observability
23:07 - Security
25:24 - Management
29:14 - Outro
Follow me on X: x.com/ayounes9
Follow me on LinkedIn: www.linkedin.com/in/aliyounes9/
Переглядів: 500
Відео
Ingest Data into the Elastic Stack with Logstash and Filebeat
Переглядів 1,2 тис.2 місяці тому
#elasticsearch #logstash #kibana #elasticsearchtutorial #fortinet #fortigate Get started with the Elastic Stack. All You Need to Get Started on the Elastic Stack: Elasticsearch, Logstash, Beats and Kibana In this lesson, we install and configure Logstash and Filebeat to ingest Fortinet Syslogs into the Elastic cluster. 00:00 - Intro 03:17 - Install and Configure Logstash 15:21 - Install and Con...
Configure Security for the Elastic Stack
Переглядів 1 тис.3 місяці тому
#elasticsearch #logstash #kibana #elasticsearchtutorial Get started with the Elastic Stack. All You Need to Get Started on the Elastic Stack: Configure Security for the Elastic Stack. In this lesson, we demonstrate how to secure the cluster with certificates. 00:00 - Intro 03:49 - Generate a CA 05:10 - Secure the Transport Layer 11:43 - Secure the HTTP Layer 18:18 - Secure Traffic between the B...
Install and Configure a Secure Elastic Stack
Переглядів 2,4 тис.5 місяців тому
#elasticsearch #logstash #kibana #elasticsearchtutorial Get started with the Elastic Stack. All You Need to Get Started on the Elastic Stack: Elasticsearch, Logstash, Beats and Kibana In this lesson, we demonstrate how to install and configure Elasticsearch, form a cluster, and install and configure Kibana. 00:00 - Intro 01:25 - Overview 01:56 - Install Elasticsearch 08:32 - Configure Elasticse...
Master the Elastic Stack: Elastic Stack Overview
Переглядів 2,5 тис.7 місяців тому
#elasticsearch #logstash #kibana Get started with the Elastic Stack. All You Need to Get Started on the Elastic Stack: Elasticsearch, Logstash, Beats and Kibana In this lesson, we explain what the Elastic Stack is, its components, architecture, usage, benefits and features. 00:00 - Introduction 01:08 - Learning Objectives 01:55 - Components 04:19 - Archtecture 05:18 - Usage 06:25 - Benefits 07:...
Ingest Cisco ASA Firewall Syslogs into the Elastic Stack
Переглядів 3,1 тис.Рік тому
#cisco #elasticsearch #logstash #kibana In this video, we ingest the Cisco ASA Syslogs into an Elasticsearch cluster using 3 methods: Logstash, Filebeat and the Elastic Agent. 00:00 - Introduction 00:53 - Tutorial lab setup 02:43 - Cisco ASA Logging Setup 03:56 - Method 1: Logstash 16:39 - Method 2: Filebeat 21:24 - Method 3: Elastic Agent 27:06 - Outro Access the Logstash configuration file on...
FortiGate SNMP Monitoring with Logstash
Переглядів 3,6 тис.Рік тому
#elasticsearch #elasticsearchtutorial #logstash #kibana #fortinet #fortigate In this video, we walk through the steps to monitor a FortiGate firewall with Logstash using the SNMP Input Plugin. Watch how to install Elasticsearch and Kibana: ua-cam.com/video/kkrLanotz1I/v-deo.html Thank you for watching! Follow my Twitter: ayounes9 Follow my LinkedIn: www.linkedin.com/in/aliyounes9/
Build a Custom Docker Image for Logstash
Переглядів 3,3 тис.Рік тому
#elasticsearch #logstash #kibana #docker #dockerfile #filebeat #metricbeat In this tutorial, we build a custom docker image for Logstash, to run containers quickly. The files are available on GitHub: github.com/ayounes9/Logstash_Docker_Image.git Check out this tutorial on how to ingest Fortigate syslogs with Logstash: ua-cam.com/video/Tp5dI-GDerM/v-deo.html Thank you for watching! Follow my Twi...
Install Elasticsearch Kibana and Logstash with Docker
Переглядів 35 тис.Рік тому
#elasticsearch #filebeat #kibana #elasticsearchtutorial #logstash #metricbeat #docker #dockercompose #dockercontainer In this video, we install Elasticsearch, Kibana, and Logstash using Docker Compose. This is a way to bring up a cluster for quick testing and development. You can get the files from my GitHub ink: github.com/ayounes9/elk-on-docker.git Watch how to install Elasticsearch and Kiban...
Enrich your Data in Elasticsearch
Переглядів 3,9 тис.Рік тому
#elasticsearch #filebeat #kibana #elasticsearchtutorial #logstash #metricbeat In this tutorial, we setup data enriching in Elasticsearch to have more insights and richer data sets that will provide more understanding and relevance. Watch how to visualize FortiGate logs on Kibana: ua-cam.com/video/03Krtx5XSlM/v-deo.html Thank you for watching! Follow my Twitter: ayounes9 Follow my Li...
Packetbeat Installation and Configuration
Переглядів 3,2 тис.Рік тому
#elasticsearch #kibana #logstash #filebeat #packetbeat #metricbeat In this video, we talk about Packetbeat, how to install and configure it to capture network traffic and analyze them in Kibana. Watch how to install Fleet Server and Elastic Agent: ua-cam.com/video/UHQrOdwUg68/v-deo.html Thank you for watching! Follow my Twitter: ayounes9
Send Email Alerts for FREE with ElastAlert2
Переглядів 11 тис.Рік тому
#elasticsearch #kibana #logstash #filebeat This video shows you how to setup ElastAlert2 to connect to your Elasticsearch cluster and send email alerts from your data that match a rule. Watch how I installed and configured Logstash to ingest FortiGate Syslogs: ua-cam.com/video/Tp5dI-GDerM/v-deo.html Thank you for watching! Follow my Twitter: ayounes9
Send Email Alerts for FREE with the Email Output Plugin in Logstash
Переглядів 6 тис.Рік тому
#elasticsearch #logstash #kibana #fortigate This is a simple way to send email alerts directly from Logstash for free. With the help of the Email Output Plugin, you can send yourself and your team alerts in real-time to get notified on the important events! Watch how I installed and configured Logstash to ingest FortiGate Syslogs: ua-cam.com/video/Tp5dI-GDerM/v-deo.html Thank you for watching! ...
Using Timelion for Bandwidth Graphs in Kibana
Переглядів 2,3 тис.2 роки тому
#elasticsearch #elasticsearchtutorial #kibana In this video, we are using Timelion to graph the bandwidth of a FortiGate firewall interface. In a previous video, I explained how to get the bandwidth stats into Elasticsearch. Check it out here: ua-cam.com/video/VGgqIVsAzhI/v-deo.html Thank you for watching! Follow my Twitter: ayounes9 Follow my Blog: www.thelionping.com/
Sending FortiGate Bandwidth Stats to Elasticsearch
Переглядів 4 тис.2 роки тому
#elasticsearch #kibana #logstash #elasticsearchtutorial #fortigate #fortinet In this tutorial, I am using a Raspberry Pi to send API GET requests to the FortiGate and grab the bandwidth stats of a specific interface. Then using Logstash, I parse the data and send it to Elasticsearch. NOTE The FortiGate needs to be running FortiOS 7.0 and above to be able to use this API. Thank you for watching!...
Set up Fleet Server and Install Elastic Agent
Переглядів 48 тис.2 роки тому
Set up Fleet Server and Install Elastic Agent
Using Index Lifecycle Management (ILM) with Logstash
Переглядів 10 тис.2 роки тому
Using Index Lifecycle Management (ILM) with Logstash
Rolling Restart of an Elasticsearch Cluster
Переглядів 3,3 тис.2 роки тому
Rolling Restart of an Elasticsearch Cluster
Visualizing FortiGate Logs on Kibana
Переглядів 10 тис.2 роки тому
Visualizing FortiGate Logs on Kibana
Setting Up Elasticsearch ILM - Index Lifecycle Management
Переглядів 31 тис.2 роки тому
Setting Up Elasticsearch ILM - Index Lifecycle Management
Setup Filebeat to Monitor Elasticsearch Logs
Переглядів 38 тис.2 роки тому
Setup Filebeat to Monitor Elasticsearch Logs
Adding Nodes to an Elasticsearch Cluster
Переглядів 17 тис.2 роки тому
Adding Nodes to an Elasticsearch Cluster
Monitor Elasticsearch with Metricbeat
Переглядів 17 тис.2 роки тому
Monitor Elasticsearch with Metricbeat
Installing and Configuring Filebeat Fortinet Module
Переглядів 16 тис.2 роки тому
Installing and Configuring Filebeat Fortinet Module
Installing and Configuring Logstash to Ingest Fortinet Syslogs
Переглядів 40 тис.2 роки тому
Installing and Configuring Logstash to Ingest Fortinet Syslogs
Installing and Configuring Elasticsearch and Kibana 8.x
Переглядів 86 тис.2 роки тому
Installing and Configuring Elasticsearch and Kibana 8.x
CCNA | Configure a Floating Static Route
Переглядів 3,6 тис.3 роки тому
CCNA | Configure a Floating Static Route
Road Made very easy .thanks
I tried same steps as shown on the video, everything seems nice and healthy, except when it comes to datastream i have no data received on my elk stack, datastream not even existing, any suggestions please or something I ve missed ?
Thank you so much for your helpful video! I was struggling with this problem for over an hour and couldn't figure it out. Your explanation was very clear and easy to follow. I finally understand how to do it now. I really appreciate you sharing your knowledge.
Can you start a project from scratch by addressing all the DevOps themes?
i have problem to install fleet server
Thank you Ali, really appreciate putting these tuts out. They are of immense help. The image and sound quality just perfect and you voice is easy to follow. FYI, you look like my friend alot, he is also Younes family :) and lives in UAE
Hi, i still not clear with the syslog parsing part, how can logstash parsed the data if you not specify the path? and can i parse the log file?
Why you don't use enrollment token utility for forming a cluster?
Very nice learning video, do you have a video on this for docker container ?
great video as always can you please say what is the requirements for each elastic node you specify?
Спасибо, братик! Помог)
I want to install configure ELK on my Production Server i have 9 server one of them is master server
the master. thank you sir.
Great series so far. Looking forward to the next one.
Thank you very much, keep it up!
Hi ali , appreciate your hard work ,i have learned a lot from you can you please create a video how to collect logs via fleet as well on your current stack,it will be very helpful.
Thank you! I am planning on making a video on Fleet server, it's in the list, but for now you can check: ua-cam.com/video/UHQrOdwUg68/v-deo.html
plz rply
plz rply
plz rply
1.[node-1] This node is a fully-formed single-node cluster with cluster UUID [rvYNhRfjRA22gZl45gHf8A], but it is configured as if to discover other nodes and form a multi-node cluster via the [discovery.seed_hosts=[172.27.1qw7.ty, 172.gj7.fg1.gy]] setting. Fully-formed clusters do not attempt to discover other nodes, and nodes with different cluster UUIDs cannot belong to the same cluster. The cluster UUID persists across restarts and can only be changed by deleting the contents of the node's data path(s). Remove the discovery configuration to suppress this message. i got above error while adding node to a existing cluster in version 8 while checking log files 2.ERROR: Failed to determine the health of the cluster. , with exit code 69 when i use below command i got above error /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s node
nice one. thank for the knowledge sharing
Thank you for sharing the config. Well Appreciated
Please Continue this great great Course and thank you very much for your efforts
Thank you! I'm trying my best. I'm going to do more videos on Kibana, cluster monitoring, and Fleet server. If you have any suggestions let me know.
@@AliYounesGo4IT I think you can go with try different integrations, alerting rules, and actual use cases like node failover ,elastic defend capapilities and any other use cases. I think elastic is getting more and more popular as a siem solution and you will be leader of you continue on this videos your channel will be as a reference
i got below error please rply plz rply plz rply and can you show the yml file of your master node | ERROR: Skipping security auto configuration because this node is configured to bootstrap or to join a multi-node cluster, which is not supported., with exit code 80
I think you need to manually configure security and make sure all the nodes are using the same CA. And maybe try the following settings in elasticsearch.yml on the new node: cluster.name: your_cluster_name node.name: your_node_name discovery.seed_hosts: ["<IP_of_existing_node1>", "<IP_of_existing_node2>"] cluster.initial_master_nodes: ["<existing_master_node_name>"]
[ERROR] 2024-11-21 06:29:06.738 [Converge PipelineAction::Create<main>] agent - Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of [ \\t\ \ ], \"#\", \"if\", [A-Za-z0-9_-], '\"', \"'\", \"}\" at line 13, column 1 (byte 103) after output { stdout {} ", :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:294:in `initialize'", "org/logstash/execution/AbstractPipelineExt.java:227:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:48:in `initialize'", "org/jruby/RubyClass.java:949:in `new'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:50:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:416:in `block in converge_state'"]} [INFO ] 2024-11-21 06:29:06.772 [LogStash::Runner] runner - Logstash shut down.
Fantastic video. I struggled all day with this stuff then I found this video and it solved all my issues
@Ali Younes .. i am able to install the kibana and elsaticsearch by following the steps which you meintioned.But post installation i am not able to access the elasticsearch ui (10.11.12.13:5601) . note : 10.11.12.13 is the sample ip. it is loading for a long time and returning in the web : This page isn’t working 10.11.12.13 didn’t send any data. ERR_EMPTY_RESPONS
Good videos. If I want to forward all types of FortiGate log like UTM(anomaly,app-control,ips, SSL,web-filter,virus),Traffic, etc., then how do I parse all types of log? Can I use the same single filebeat machine to do that? Also, in Elasticsearch, should I need different index for these logs?
Yes, you can parse UTM logs with the same Fortinet Filebeat module. The UTMs will be available for search when you choose the type of traffic you're looking for: Traffic/UTM/system/etc.. In Elasticsearch, it's up to you, you can have different indexes for each type of traffic, but that will be extra configurations. You can use Kibana filters to query and search for each type. Hope that helps!
@@AliYounesGo4IT Thank you...
doesnt work
sir how can i add node with our self sigh certificate like CA Authoerity certificate which i have generated using elasticsearch ?
this config files are discontinued , dont use this video to install ELK
شكرا علي استفدة منك. لعمل log في الشركة شكرا جزيلا. حبذ. لو. تركزلنا على fortigate. و logstash.
جَزَاكَ اللَّهُ خَيْرًا
Hi, I have watched all your videos, you explain very clearly. I don't know if it is appropriate to go ahead with a question. As you recommended I have a cluster of 3 servers for elastic, Feet Server separate and Kibana also separate. I find it strange that when I shut down one of the servers in the Elasticsearch cluster or simply disable the elasticsearch service, Fleet stops working. I just don't understand. Any suggestions?
Sorry for the late reply. The only thing I can think of is that your Fleet server might not be pointing to all 3 nodes and pointing to one only.
Could you tell me how to make the fleet server point to all 3?
Very clear, thank you very much. Greetings from Colombia
Hi Thank you for all your Videos in Elastic, can you make a video on how to Integrate FortiEDR Logs using syslog going to Elastic SIEM? Thank You in Advance: )
Great video. What is the simulation software you are using? It’s amazing
just noticed Cisco Packet Tracer.
Great Content Thanks a lot for this clear demo.
Keep Going Bro, We Need People like you, humble and ready to share their knowledge ... If possible, to make a series of the 200-301 Volume 1-2 All the Best Ali
where is the elastalert-create-index? it is not found anywhere in the bin folder. 😵
The backup file exported in this way does not export the "config system admin", do you know how I can make this item exported together with the API?
any helps how to add metricbeat as docker to the stack for cluster monitoring?
How can I take data from MySQL db?
hello sir i am getting this issue when i click on fleet "Kibana cannot connect to the Elastic Package Registry, which provides Elastic Agent integrations Ensure the proxy server(opens in a new tab or window) or your own registry(opens in a new tab or window) is configured correctly, or try again later. " how can i resolve this issue ?
i wish there were a like button which can generate tons of likes..i would do that on this video!! you have solve my biggest problem!!thanks a lot boss
Glad it helped!
Hi Ali, fantastic video - works like a charm. Thx for the effort. I have one or two questions regarding adding additional containers to the docker-compose file. If i add additional containers, i get the following error, validating /home/test/elk/docker-compose.yml: services.logstash Additional property filebeat is not allowed. Can file beat just be added as a separate container instead of adding it to the docker-compose file?
You can add it as a separate container, but I think the error is because Filebeat has to be on the same level as Logstash under the "services" key in the docker-compose.yml file.
Hi, ca we send log from fortigate directly to logstash/elasticsearch withtout filebeat? I mean, Why do most tutorials always use Filebeat?
Yes you can send to Logstash without Filebeat. I have this tutorial explaining how to install Logstash and send Fortigate logs to it: ua-cam.com/video/Tp5dI-GDerM/v-deo.htmlsi=9XJLRCBk_R91-BZk
i have question about ILM is it possible to create lifecycle policy for index pattern not just an index
I made a video on ILM, check it out here: ua-cam.com/video/Ybbk44mkOE0/v-deo.htmlsi=X9WjOrNFA6Mv106e
Thank you, Ali, for this video, useful one.
Still valid in 2024! Thank you for the help!