Cisco ASA Netflow in Elasticsearch

Using Netflow, you can visualize your network traffic and use the collected data to analyze conections in case of troubles (which is what I use it for). All kinds of collectors are on the market, most paid applications, but why not use ELK for this and visualize your traffic using Kibana?

Continue reading “Cisco ASA Netflow in Elasticsearch”

WIP: Exchange Server Monitoring

It’s still a Work In Progress, but I didn’t want to keep this from you. Using ELK and Filebeat, I want to monitor what is going in and out of my Microsoft Exchange Server. Eventually I want to see what e-mail is flowing trough my Edge Server to my Mailbox Server and what e-mail is blocked (and in what amounts).

I’ll keep you posted!

exchange_dashboard

Cisco ASA alerts and Kibana

KibanaToday we will be sending alerts from my Cisco ASA firewall to Kibana. As I was looking how to configure this, I found some examples of how to do this, but none of them really worked, so I started “hobbying” myself and created something that works really well.

Continue reading “Cisco ASA alerts and Kibana”

Apache access logs in Kibana

KibanaI needed a more convenient way to view my Apache access logs, other than tailing the access logs files on my webserver. Why not use Kibana for this? It not only shows you the access log lines, it also lets you create nice graphs about visitors, response codes, user agents, etcetera.

Continue reading “Apache access logs in Kibana”

Webalizer and virtual hosts

WebalizerA very commonly used statstics program for the Apache webserver is the webalizer program that analizes httpd log-files and creates site statistics from that. But standard it’s configured for only one domain. As I am running multiple domains on my RedHat Enterprise Linux machine and want seperate statistics for them, some work had to be done.

Continue reading “Webalizer and virtual hosts”