Elastic Locked Up: ื”ืคืขืœืช ืืคืฉืจื•ื™ื•ืช ืื‘ื˜ื—ืช ืืฉื›ื•ืœ Elasticsearch ืœื’ื™ืฉื” ืžื‘ืคื ื™ื ื•ืžื‘ื—ื•ืฅ

Elastic Locked Up: ื”ืคืขืœืช ืืคืฉืจื•ื™ื•ืช ืื‘ื˜ื—ืช ืืฉื›ื•ืœ Elasticsearch ืœื’ื™ืฉื” ืžื‘ืคื ื™ื ื•ืžื‘ื—ื•ืฅ

Elastic Stack ื”ื•ื ื›ืœื™ ืžื•ื›ืจ ื‘ืฉื•ืง ืžืขืจื›ื•ืช ื”-SIEM (ืœืžืขืฉื”, ืœื ืจืง ืื•ืชื). ื–ื” ื™ื›ื•ืœ ืœืืกื•ืฃ ื”ืจื‘ื” ื ืชื•ื ื™ื ื‘ื’ื“ืœื™ื ืฉื•ื ื™ื, ื’ื ืจื’ื™ืฉื™ื ื•ื’ื ืœื ืžืื•ื“ ืจื’ื™ืฉื™ื. ื–ื” ืœื ืœื’ืžืจื™ ื ื›ื•ืŸ ืื ื”ื’ื™ืฉื” ืœืืœืžื ื˜ื™ื ื”ืืœืกื˜ื™ื™ื ืขืฆืžื ืื™ื ื” ืžื•ื’ื ืช. ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื›ืœ ื”ืืœืžื ื˜ื™ื ืฉืœ Elastic ืžื—ื•ืฅ ืœืงื•ืคืกื” (ืืกืคื ื™ Elasticsearch, Logstash, Kibana ื•-Beats) ืคื•ืขืœื™ื ืขืœ ืคืจื•ื˜ื•ืงื•ืœื™ื ืคืชื•ื—ื™ื. ื•ื‘ืงื™ื‘ืื ื” ืขืฆืžื”, ื”ืื™ืžื•ืช ืžื•ืฉื‘ืช. ื ื™ืชืŸ ืœืื‘ื˜ื— ืืช ื›ืœ ื”ืื™ื ื˜ืจืืงืฆื™ื•ืช ื”ืœืœื• ื•ื‘ืžืืžืจ ื–ื” ื ืกืคืจ ืœื›ื ื›ื™ืฆื“ ืœืขืฉื•ืช ื–ืืช. ืžื˜ืขืžื™ ื ื•ื—ื•ืช, ื—ื™ืœืงื ื• ืืช ื”ื ืจื˜ื™ื‘ ืœ-3 ื‘ืœื•ืงื™ื ืกืžื ื˜ื™ื™ื:

  • ืžื•ื“ืœ ื’ื™ืฉื” ืœื ืชื•ื ื™ื ืžื‘ื•ืกืก ืชืคืงื™ื“ื™ื
  • ืื‘ื˜ื—ืช ื ืชื•ื ื™ื ื‘ืชื•ืš ืืฉื›ื•ืœ Elasticsearch
  • ืื‘ื˜ื—ืช ื ืชื•ื ื™ื ืžื—ื•ืฅ ืœืืฉื›ื•ืœ Elasticsearch

ืคืจื˜ื™ื ืžืชื—ืช ืœื—ืชื•ืš.

ืžื•ื“ืœ ื’ื™ืฉื” ืœื ืชื•ื ื™ื ืžื‘ื•ืกืก ืชืคืงื™ื“ื™ื

ืื ืชืชืงื™ืŸ ืืช Elasticsearch ื•ืœื ืชื›ื•ื•ืŸ ืื•ืชื• ื‘ืฉื•ื ืฆื•ืจื”, ื”ื’ื™ืฉื” ืœื›ืœ ื”ืื™ื ื“ืงืกื™ื ืชื”ื™ื” ืคืชื•ื—ื” ืœื›ื•ืœื. ื•ื‘ื›ืŸ, ืื• ื›ืืœื” ืฉื™ื›ื•ืœื™ื ืœื”ืฉืชืžืฉ ื‘ืชืœืชืœ. ื›ื“ื™ ืœื”ื™ืžื ืข ืžื›ืš, ืœ- Elasticsearch ื™ืฉ ืžื•ื“ืœ ืœื—ื™ืงื•ื™ ืฉื–ืžื™ืŸ ื”ื—ืœ ืžืžื ื•ื™ Basic (ืฉื”ื•ื ื‘ื—ื™ื ื). ืกื›ืžื˜ื™ืช ื–ื” ื ืจืื” ื‘ืขืจืš ื›ืš:

Elastic Locked Up: ื”ืคืขืœืช ืืคืฉืจื•ื™ื•ืช ืื‘ื˜ื—ืช ืืฉื›ื•ืœ Elasticsearch ืœื’ื™ืฉื” ืžื‘ืคื ื™ื ื•ืžื‘ื—ื•ืฅ

ืžื” ื‘ืชืžื•ื ื”

  • ืžืฉืชืžืฉื™ื ื”ื ื›ืœ ืžื™ ืฉื™ื›ื•ืœ ืœื”ืชื—ื‘ืจ ื‘ืืžืฆืขื•ืช ื”ืื™ืฉื•ืจื™ื ืฉืœื”ื.
  • ืชืคืงื™ื“ ื”ื•ื ืื•ืกืฃ ืฉืœ ื–ื›ื•ื™ื•ืช.
  • ื–ื›ื•ื™ื•ืช ื”ืŸ ืงื‘ื•ืฆื” ืฉืœ ื”ืจืฉืื•ืช.
  • ื”ืจืฉืื•ืช ื”ืŸ ื”ืจืฉืื•ืช ื›ืชื™ื‘ื”, ืงืจื™ืื”, ืžื—ื™ืงื” ื•ื›ื•'. (ืจืฉื™ืžื” ืžืœืื” ืฉืœ ื”ืจืฉืื•ืช)
  • ืžืฉืื‘ื™ื ื”ื ืื™ื ื“ืงืกื™ื, ืžืกืžื›ื™ื, ืฉื“ื•ืช, ืžืฉืชืžืฉื™ื ื•ื™ืฉื•ื™ื•ืช ืื—ืกื•ืŸ ืื—ืจื•ืช (ื”ืžื•ื“ืœ ืœื—ื™ืงื•ื™ ืœืžืฉืื‘ื™ื ืžืกื•ื™ืžื™ื ื–ืžื™ืŸ ืจืง ืขื ืžื ื•ื™ื™ื ื‘ืชืฉืœื•ื).

ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื™ืฉ ืœ-Elasticsearch ืžืฉืชืžืฉื™ ืงื•ืคืกื, ืฉืืœื™ื• ื”ื ืžื—ื•ื‘ืจื™ื ืชืคืงื™ื“ื™ ืงื•ืคืกื”. ืœืื—ืจ ืฉืชืคืขื™ืœ ืืช ื”ื’ื“ืจื•ืช ื”ืื‘ื˜ื—ื”, ืชื•ื›ืœ ืœื”ืชื—ื™ืœ ืœื”ืฉืชืžืฉ ื‘ื”ืŸ ื‘ืื•ืคืŸ ืžื™ื™ื“ื™.

ื›ื“ื™ ืœื”ืคืขื™ืœ ืื‘ื˜ื—ื” ื‘ื”ื’ื“ืจื•ืช Elasticsearch, ืขืœื™ืš ืœื”ื•ืกื™ืฃ ืื•ืชื” ืœืงื•ื‘ืฅ ื”ืชืฆื•ืจื” (ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื–ื” elasticsearch/config/elasticsearch.yml) ืฉื•ืจื” ื—ื“ืฉื”:

xpack.security.enabled: true

ืœืื—ืจ ืฉื™ื ื•ื™ ืงื•ื‘ืฅ ื”ืชืฆื•ืจื”, ื”ืคืขืœ ืื• ื”ืคืขืœ ืžื—ื“ืฉ ืืช Elasticsearch ื›ื“ื™ ืฉื”ืฉื™ื ื•ื™ื™ื ื™ื™ื›ื ืกื• ืœืชื•ืงืฃ. ื”ืฉืœื‘ ื”ื‘ื ื”ื•ื ื”ืงืฆืืช ืกื™ืกืžืื•ืช ืœืžืฉืชืžืฉื™ ื”ืชื™ื‘ื”. ื‘ื•ืื• ื ืขืฉื” ื–ืืช ื‘ืื•ืคืŸ ืื™ื ื˜ืจืืงื˜ื™ื‘ื™ ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื” ืœืžื˜ื”:

[elastic@node1 ~]$ ./elasticsearch/bin/elasticsearch-setup-passwords interactive
Initiating the setup of passwords for reserved users elastic,apm_system,kibana,logstash_system,beats_system,remote_monitoring_user.
You will be prompted to enter passwords as the process progresses.
Please confirm that you would like to continue [y/N]y


Enter password for [elastic]:
Reenter password for [elastic]:
Enter password for [apm_system]:
Reenter password for [apm_system]:
Enter password for [kibana]:
Reenter password for [kibana]:
Enter password for [logstash_system]:
Reenter password for [logstash_system]:
Enter password for [beats_system]:
Reenter password for [beats_system]:
Enter password for [remote_monitoring_user]:
Reenter password for [remote_monitoring_user]:
Changed password for user [apm_system]
Changed password for user [kibana]
Changed password for user [logstash_system]
Changed password for user [beats_system]
Changed password for user [remote_monitoring_user]
Changed password for user [elastic]

ืื ื• ื‘ื•ื“ืงื™ื:

[elastic@node1 ~]$ curl -u elastic 'node1:9200/_cat/nodes?pretty'
Enter host password for user 'elastic':
192.168.0.2 23 46 14 0.28 0.32 0.18 dim * node1

ืืชื” ื™ื›ื•ืœ ืœื˜ืคื•ื— ืœืขืฆืžืš ืขืœ ื”ืฉื›ื - ื”ื”ื’ื“ืจื•ืช ื‘ืฆื“ Elasticsearch ื”ื•ืฉืœืžื•. ืขื›ืฉื™ื• ื”ื’ื™ืข ื”ื–ืžืŸ ืœื”ื’ื“ื™ืจ ืืช Kibana. ืื ืชืคืขื™ืœ ืื•ืชื• ื›ืขืช, ื™ื•ืคื™ืขื• ืฉื’ื™ืื•ืช, ื•ืœื›ืŸ ื—ืฉื•ื‘ ืœื™ืฆื•ืจ ื—ื ื•ืช ืžืคืชื—ื•ืช. ื–ื” ื ืขืฉื” ื‘ืฉืชื™ ืคืงื•ื“ื•ืช (ืžืฉืชืžืฉ ืงื™ื‘ืื ื” ื•ื”ืกื™ืกืžื” ืฉื”ื•ื–ื ื” ื‘ืฉืœื‘ ื™ืฆื™ืจืช ื”ืกื™ืกืžื” ื‘- Elasticsearch):

[elastic@node1 ~]$ ./kibana/bin/kibana-keystore add elasticsearch.username
[elastic@node1 ~]$ ./kibana/bin/kibana-keystore add elasticsearch.password

ืื ื”ื›ืœ ื ื›ื•ืŸ, Kibana ื™ืชื—ื™ืœ ืœื‘ืงืฉ ื›ื ื™ืกื” ื•ืกื™ืกืžื”. ื”ืžื ื•ื™ Basic ื›ื•ืœืœ ืžื•ื“ืœ ืœื—ื™ืงื•ื™ ื”ืžื‘ื•ืกืก ืขืœ ืžืฉืชืžืฉื™ื ืคื ื™ืžื™ื™ื. ื”ื—ืœ ืž-Gold, ื ื™ืชืŸ ืœื—ื‘ืจ ืžืขืจื›ื•ืช ืื™ืžื•ืช ื—ื™ืฆื•ื ื™ื•ืช - LDAP, PKI, Active Directory ื•ืžืขืจื›ื•ืช ื›ื ื™ืกื” ื™ื—ื™ื“ื”.

Elastic Locked Up: ื”ืคืขืœืช ืืคืฉืจื•ื™ื•ืช ืื‘ื˜ื—ืช ืืฉื›ื•ืœ Elasticsearch ืœื’ื™ืฉื” ืžื‘ืคื ื™ื ื•ืžื‘ื—ื•ืฅ

ื ื™ืชืŸ ื’ื ืœื”ื’ื‘ื™ืœ ืืช ื–ื›ื•ื™ื•ืช ื”ื’ื™ืฉื” ืœืื•ื‘ื™ื™ืงื˜ื™ื ื‘ืชื•ืš Elasticsearch. ืขื ื–ืืช, ื›ื“ื™ ืœืขืฉื•ืช ืืช ืื•ืชื• ื”ื“ื‘ืจ ืขื‘ื•ืจ ืžืกืžื›ื™ื ืื• ืฉื“ื•ืช, ืชืฆื˜ืจืš ืžื ื•ื™ ื‘ืชืฉืœื•ื (ืžื•ืชืจื•ืช ื–ื• ืžืชื—ื™ืœื” ื‘ืจืžืช ืคืœื˜ื™ื ื•ื). ื”ื’ื“ืจื•ืช ืืœื• ื–ืžื™ื ื•ืช ื‘ืžืžืฉืง Kibana ืื• ื‘ืืžืฆืขื•ืช API ืื‘ื˜ื—ื”. ืืชื” ื™ื›ื•ืœ ืœื‘ื“ื•ืง ื“ืจืš ื”ืชืคืจื™ื˜ Dev Tools ื”ืžื•ื›ืจ ื›ื‘ืจ:

ื™ืฆื™ืจืช ืชืคืงื™ื“

PUT /_security/role/ruslan_i_ludmila_role
{
  "cluster": [],
  "indices": [
    {
      "names": [ "ruslan_i_ludmila" ],
      "privileges": ["read", "view_index_metadata"]
    }
  ]
}

ื™ืฆื™ืจืช ืžืฉืชืžืฉ

POST /_security/user/pushkin
{
  "password" : "nataliaonelove",
  "roles" : [ "ruslan_i_ludmila_role", "kibana_user" ],
  "full_name" : "Alexander Pushkin",
  "email" : "[email protected]",
  "metadata" : {
    "hometown" : "Saint-Petersburg"
  }
}

ืื‘ื˜ื—ืช ื ืชื•ื ื™ื ื‘ืชื•ืš ืืฉื›ื•ืœ Elasticsearch

ื›ืืฉืจ Elasticsearch ืคื•ืขืœ ื‘ืืฉื›ื•ืœ (ืฉื ืคื•ืฆื”), ื”ื’ื“ืจื•ืช ื”ืื‘ื˜ื—ื” ื‘ืชื•ืš ื”ืืฉื›ื•ืœ ื”ื•ืคื›ื•ืช ื—ืฉื•ื‘ื•ืช. ืœืชืงืฉื•ืจืช ืžืื•ื‘ื˜ื—ืช ื‘ื™ืŸ ืฆืžืชื™ื, Elasticsearch ืžืฉืชืžืฉ ื‘ืคืจื•ื˜ื•ืงื•ืœ TLS. ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืื™ื ื˜ืจืืงืฆื™ื” ืžืื•ื‘ื˜ื—ืช ื‘ื™ื ื™ื”ื, ืืชื” ืฆืจื™ืš ืื™ืฉื•ืจ. ืื ื• ื™ื•ืฆืจื™ื ืื™ืฉื•ืจ ื•ืžืคืชื— ืคืจื˜ื™ ื‘ืคื•ืจืžื˜ PEM:

[elastic@node1 ~]$ ./elasticsearch/bin/elasticsearch-certutil ca --pem

ืœืื—ืจ ื‘ื™ืฆื•ืข ื”ืคืงื•ื“ื” ืœืžืขืœื”, ื‘ืกืคืจื™ื™ื” /../elasticsearch ื™ื•ืคื™ืข ืืจื›ื™ื•ืŸ elastic-stack-ca.zip. ื‘ืชื•ื›ื• ืชืžืฆืื• ืชืขื•ื“ื” ื•ืžืคืชื— ืคืจื˜ื™ ืขื ื”ืจื—ื‘ื•ืช crt ะธ ืžืคืชื— ื‘ื”ืชืืžื”. ืจืฆื•ื™ ืœืฉื™ื ืื•ืชื ืขืœ ืžืฉืื‘ ืžืฉื•ืชืฃ, ืฉืืžื•ืจ ืœื”ื™ื•ืช ื ื’ื™ืฉ ืžื›ืœ ื”ืฆืžืชื™ื ื‘ืืฉื›ื•ืœ.

ื›ืœ ืฆื•ืžืช ื–ืงื•ืง ื›ืขืช ืœืื™ืฉื•ืจื™ื ื•ืžืคืชื—ื•ืช ืคืจื˜ื™ื™ื ืžืฉืœื• ื”ืžื‘ื•ืกืกื™ื ืขืœ ืืœื” ืฉื‘ืกืคืจื™ื™ื” ื”ืžืฉื•ืชืคืช. ื‘ืขืช ื‘ื™ืฆื•ืข ื”ืคืงื•ื“ื”, ืชืชื‘ืงืฉ ืœื”ื’ื“ื™ืจ ืกื™ืกืžื”. ืืชื” ื™ื›ื•ืœ ืœื”ื•ืกื™ืฃ ืืคืฉืจื•ื™ื•ืช ื ื•ืกืคื•ืช -ip ื•-dns ืœืื™ืžื•ืช ืžืœืื” ืฉืœ ืฆืžืชื™ื ื‘ืื™ื ื˜ืจืืงืฆื™ื”.

[elastic@node1 ~]$ ./elasticsearch/bin/elasticsearch-certutil cert --ca-cert /shared_folder/ca/ca.crt --ca-key /shared_folder/ca/ca.key

ื›ืชื•ืฆืื” ืžื‘ื™ืฆื•ืข ื”ืคืงื•ื“ื” ื ืงื‘ืœ ืื™ืฉื•ืจ ื•ืžืคืชื— ืคืจื˜ื™ ื‘ืคื•ืจืžื˜ PKCS#12, ืžื•ื’ืŸ ื‘ืกื™ืกืžื”. ื›ืœ ืžื” ืฉื ื•ืชืจ ื”ื•ื ืœื”ืขื‘ื™ืจ ืืช ื”ืงื•ื‘ืฅ ืฉื ื•ืฆืจ p12 ืœืกืคืจื™ื™ืช ื”ืชืฆื•ืจื”:

[elastic@node1 ~]$ mv elasticsearch/elastic-certificates.p12 elasticsearch/config

ื”ื•ืกืฃ ืกื™ืกืžื” ืœืื™ืฉื•ืจ ื‘ืคื•ืจืžื˜ p12 ื‘-keystore ื•ื‘-truststore ื‘ื›ืœ ืฆื•ืžืช:

[elastic@node1 ~]$ ./elasticsearch/bin/elasticsearch-keystore add xpack.security.transport.ssl.keystore.secure_password
[elastic@node1 ~]$ ./elasticsearch/bin/elasticsearch-keystore add xpack.security.transport.ssl.truststore.secure_password

ื›ื‘ืจ ื™ื“ื•ืข elasticsearch.yml ื›ืœ ืžื” ืฉื ื•ืชืจ ื”ื•ื ืœื”ื•ืกื™ืฃ ืฉื•ืจื•ืช ืขื ื ืชื•ื ื™ ืื™ืฉื•ืจ:

xpack.security.transport.ssl.enabled: true
xpack.security.transport.ssl.verification_mode: certificate
xpack.security.transport.ssl.keystore.path: elastic-certificates.p12
xpack.security.transport.ssl.truststore.path: elastic-certificates.p12

ืื ื• ืžืฉื™ืงื™ื ืืช ื›ืœ ืฆืžืชื™ Elasticsearch ื•ืžื‘ืฆืขื™ื ืชืœืชืœ. ืื ื”ื›ืœ ื‘ื•ืฆืข ื›ื”ืœื›ื”, ืชื•ื—ื–ืจ ืชื’ื•ื‘ื” ืขื ืžืกืคืจ ืฆืžืชื™ื:

[elastic@node1 ~]$ curl node1:9200/_cat/nodes -u elastic:password                                                                                    
172.18.0.3 43 75 4 0.00 0.05 0.05 dim * node2                                                                                                                     
172.18.0.4 21 75 3 0.00 0.05 0.05 dim - node3                                                                                                                     
172.18.0.2 39 75 4 0.00 0.05 0.05 dim - node1

ื™ืฉื ื” ืืคืฉืจื•ืช ืื‘ื˜ื—ื” ื ื•ืกืคืช - ืกื™ื ื•ืŸ ื›ืชื•ื‘ื•ืช IP (ื–ืžื™ืŸ ื‘ืžื ื•ื™ื™ื ืžืจืžืช ื–ื”ื‘). ืžืืคืฉืจ ืœืš ืœื™ืฆื•ืจ ืจืฉื™ืžื•ืช ืœื‘ื ื•ืช ืฉืœ ื›ืชื•ื‘ื•ืช IP ืฉืžื”ืŸ ืืชื” ืจืฉืื™ ืœื’ืฉืช ืœืฆืžืชื™ื.

ืื‘ื˜ื—ืช ื ืชื•ื ื™ื ืžื—ื•ืฅ ืœืืฉื›ื•ืœ Elasticsearch

ืžื—ื•ืฅ ืœืืฉื›ื•ืœ ืคื™ืจื•ืฉื• ื—ื™ื‘ื•ืจ ื›ืœื™ื ื—ื™ืฆื•ื ื™ื™ื: Kibana, Logstash, Beats ืื• ืœืงื•ื—ื•ืช ื—ื™ืฆื•ื ื™ื™ื ืื—ืจื™ื.

Elastic Locked Up: ื”ืคืขืœืช ืืคืฉืจื•ื™ื•ืช ืื‘ื˜ื—ืช ืืฉื›ื•ืœ Elasticsearch ืœื’ื™ืฉื” ืžื‘ืคื ื™ื ื•ืžื‘ื—ื•ืฅ

ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืชืžื™ื›ื” ืขื‘ื•ืจ https (ื‘ืžืงื•ื http), ื”ื•ืกืฃ ืฉื•ืจื•ืช ื—ื“ืฉื•ืช ืืœ elasticsearch.yml:

xpack.security.http.ssl.enabled: true
xpack.security.http.ssl.keystore.path: elastic-certificates.p12
xpack.security.http.ssl.truststore.path: elastic-certificates.p12

ื›ื™ ื”ืื™ืฉื•ืจ ืžื•ื’ืŸ ื‘ืกื™ืกืžื”, ื”ื•ืกืฃ ืื•ืชื• ืœืžืื’ืจ ื”ืžืคืชื—ื•ืช ื•ืœืžื—ืกืŸ ื”ืืžื•ืŸ ื‘ื›ืœ ืฆื•ืžืช:

[elastic@node1 ~]$ ./elasticsearch/bin/elasticsearch-keystore add xpack.security.http.ssl.keystore.secure_password
[elastic@node1 ~]$ ./elasticsearch/bin/elasticsearch-keystore add xpack.security.http.ssl.truststore.secure_password

ืœืื—ืจ ื”ื•ืกืคืช ื”ืžืคืชื—ื•ืช, ืฆืžืชื™ Elasticsearch ืžื•ื›ื ื™ื ืœื”ืชื—ื‘ืจ ื‘ืืžืฆืขื•ืช https. ืขื›ืฉื™ื• ืืคืฉืจ ืœื”ืฉื™ืง ืื•ืชื.

ื”ืฉืœื‘ ื”ื‘ื ื”ื•ื ืœื™ืฆื•ืจ ืžืคืชื— ืœื—ื™ื‘ื•ืจ Kibana ื•ืœื”ื•ืกื™ืฃ ืื•ืชื• ืœืชืฆื•ืจื”. ื‘ื”ืชื‘ืกืก ืขืœ ื”ืื™ืฉื•ืจ ืฉื›ื‘ืจ ื ืžืฆื ื‘ืกืคืจื™ื™ื” ื”ืžืฉื•ืชืคืช, ื ื™ืฆื•ืจ ืื™ืฉื•ืจ ื‘ืคื•ืจืžื˜ PEM (PKCS#12 Kibana, Logstash ื•-Beats ืขื“ื™ื™ืŸ ืœื ืชื•ืžื›ื™ื):

[elastic@node1 ~]$ ./elasticsearch/bin/elasticsearch-certutil cert --ca-cert /shared_folder/ca/ca.crt --ca-key /shared_folder/ca/ca.key --pem

ื›ืœ ืžื” ืฉื ื•ืชืจ ื”ื•ื ืœืคืจื•ืง ืืช ื”ืžืคืชื—ื•ืช ืฉื ื•ืฆืจื• ืœืชื•ืš ื”ืชื™ืงื™ื” ืขื ืชืฆื•ืจืช Kibana:

[elastic@node1 ~]$ unzip elasticsearch/certificate-bundle.zip -d kibana/config

ื”ืžืคืชื—ื•ืช ื ืžืฆืื™ื ืฉื, ืื– ื›ืœ ืžื” ืฉื ื•ืชืจ ื”ื•ื ืœืฉื ื•ืช ืืช ืชืฆื•ืจืช Kibana ื›ืš ืฉื™ืชื—ื™ืœ ืœื”ืฉืชืžืฉ ื‘ื”ื. ื‘ืงื•ื‘ืฅ ื”ืชืฆื•ืจื” kibana.yml, ืฉื ื” http ืœ-https ื•ื”ื•ืกืฃ ืฉื•ืจื•ืช ืขื ื”ื’ื“ืจื•ืช ื—ื™ื‘ื•ืจ SSL. ืฉืœื•ืฉ ื”ืฉื•ืจื•ืช ื”ืื—ืจื•ื ื•ืช ืงื•ื‘ืขื•ืช ืชืงืฉื•ืจืช ืžืื•ื‘ื˜ื—ืช ื‘ื™ืŸ ื”ื“ืคื“ืคืŸ ืฉืœ ื”ืžืฉืชืžืฉ ืœ-Kibana.

elasticsearch.hosts: ["https://${HOSTNAME}:9200"]
elasticsearch.ssl.certificateAuthorities: /shared_folder/ca/ca.crt
elasticsearch.ssl.verificationMode: certificate
server.ssl.enabled: true
server.ssl.key: /../kibana/config/instance/instance.key
server.ssl.certificate: /../kibana/config/instance/instance.crt

ื›ืš, ื”ื”ื’ื“ืจื•ืช ื”ื•ืฉืœืžื• ื•ื”ื’ื™ืฉื” ืœื ืชื•ื ื™ื ื‘ืืฉื›ื•ืœ Elasticsearch ืžื•ืฆืคื ืช.

ืื ื™ืฉ ืœืš ืฉืืœื•ืช ืœื’ื‘ื™ ื”ื™ื›ื•ืœื•ืช ืฉืœ Elastic Stack ืขืœ ืžื ื•ื™ื™ื ื‘ื—ื™ื ื ืื• ื‘ืชืฉืœื•ื, ืžืฉื™ืžื•ืช ื ื™ื˜ื•ืจ ืื• ื™ืฆื™ืจืช ืžืขืจื›ืช SIEM, ื”ืฉืืจ ื‘ืงืฉื” ืœ ื˜ื•ืคืก ืžืฉื•ื‘ ื‘ืืชืจ ืฉืœื ื•.

ืขื•ื“ ืžืืžืจื™ื ืฉืœื ื• ืขืœ Elastic Stack ื‘-Habrรฉ:

ื”ื‘ื ืช ืœืžื™ื“ืช ืžื›ื•ื ื” ื‘ืžื—ืกื ื™ืช ื”ืืœืกื˜ื™ืช (ื”ืžื›ื•ื ื” Elasticsearch, aka ELK)

ื’ื•ื“ืœ Elasticsearch

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”