ä»åã¯ãã¹ãŠã®ããã¥ã¢ã«ãELK5ãŸãã¯ããããå€ããã®ã§ãããã以åã®ããŒãžã§ã³ã®ãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ããããããŸããã§ããã ç§ã¯ãæãææãªãµããŒãæéïŒã§ããã°ææ°ã®å®å®çïŒã§ãœãããŠã§ã¢ãå ¥æãããã£ãã®ã§ãã
ãã®çµæãä»åŸãã¹ãŠã®èŠçãç¹°ãè¿ããã«å®ç§ãªåæ¥ãç¹°ãè¿ãããšãã§ããããã«ããããã«ãç§ã¯ããªããšå ±æãã段éçãªããŒãã·ãŒããæžããªããã°ãªããŸããã
ä»æ¥ãMikrotikïŒRouterOSïŒãSuricata 4.1ãElasticsearch + Filebeat + Kibana 6.5ã
åå ãã代ããã«
æ¡ä»¶ïŒ
- ãã¹ãAã®ä»®æ³ãã·ã³ã«ããi386ã®MikrotikãMikrotikã®ãã¹ãŠã®ã€ã³ã¿ãŒãã§ãŒã¹ã¯VLANã«æ£åšããŠããããã¹ãã«ã¯1ã€ã®ç©çãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ãŒã¹ããããŸãã
- åäžã®ç©çãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ãåãããã¹ãBã®IDS / IPS / NMSã®ç¡æãªãœãŒã¹ã
- 20ã¡ã¬ãã€ãã®ãã£ãã«åºåã
- Mikrotikã®å€éšã€ã³ã¿ãŒãã§ã€ã¹ãééãããã©ãã£ãã¯ã«é¢ããåæãåä¿¡ãããã
- ããã³ã«ãŒãã«ãšFIGã³ããã¯ã®äºç®ã
- æéã®ããããªãäžå®ã®ç©ºãæéã
ããã§ã¯ãIDS / IPS / NMSãšã¯äœãããªãå¿ èŠãªã®ããäœãèµ·ããã®ãã«ã€ããŠã¯èª¬æããŸããã 誰ãç§ãªãã§ãããç¥ã£ãŠããŸãããããŠãç¥ããªã圌ã¯ã°ãŒã°ã«ã«ãªããŸãã
ãŸããç§ã¯SnortãšSuricataã®ã©ã¡ããéžæããããæ£åœåãããåŸè ãæ¯æããŸãã ããã¯å¥œã¿ã®åé¡ã§ãã
ãããããã®ä»çµã¿ãè¡šé¢çã«èª¬æããŸãã
Suricataã¯ã©ãããããããã©ãã£ãã¯ãåãåããŸãã 3ã€ã®ãªãã·ã§ã³ããããŸããaïŒã€ã³ã©ã€ã³ã¢ãŒãã§èªåã«æž¡ããbïŒã¹ã€ããããŒããããã©ãã£ãã¯ã®ã³ããŒãåä¿¡ãããcïŒãã©ãã£ãã¯ãå«ããã³ããåæããã Suricataã¯åä¿¡ãããã©ãã£ãã¯ãåæããåæã«åºã¥ããŠããã®ãã©ãã£ãã¯ã§èŠã€ãã£ãããŒã¿ãæäŸããŸãã
Suricataã¯JSONã§ããŒã¿ãçºè¡ã§ããŸãã ãããã£ãŠãæ§é åãããããŒã¿ãããã°ãåŠçãã·ã¹ãã åãåæãèŠèŠåã®ããã«äœããã®ã·ã¹ãã ã«éãããšãã§ããŸãã
ç§ãç解ããéããããŒã¿ã®åæãšèŠèŠåã«ã€ããŠã¯ããã®åéã®å°é家ã§ãªããŠããELKã¹ã¿ãã¯ã¯å®ç§ã§ãã ELKã¹ã¿ãã¯ã¯å ã ãElasticsearchãLogstashãKibanaã§æ§æãããŠããŸããã ããã§Beatãè¿œå ãããŸããïŒããŒã¿ãœãŒã¹ãšLogstashãŸãã¯Elasticsearchã®éã®ä»²ä»ãšããŠæ©èœããã€ã³ã¿ãŒãã§ã€ã¹ããã°ã©ã ã®ãã¡ããªïŒã ä»åŸã¯ãBeatãElasticsearchã«çŽæ¥ããŒã¿ãå®å šã«äŸçµŠããElasticsearchããããå®å šã«æ¶è²»ãããããLogstashã¯ãªãã£ããšèšããŸãã Elasticsearchã¯ãåãŸããããŒã¿ãELKã¹ã¿ãã¯å šäœã®Webã€ã³ã¿ãŒãã§ã€ã¹ã§ããKibanaã«è»¢éããŸãã Kibanaã¯ãFilebeatããæž¡ããããã³ãã¬ãŒãã䜿çšããŠããŠãŒã¶ãŒã«ããŒã¿ã®èŠèŠåãããããããã·ã¥ããŒããæäŸããŸãã ElasticsearchãLogstashãBeatãããã³Kibanaã1ã€ã®ã¡ãŒã«ãŒã®ææã§ãããšããäºå®ãèæ ®ãããšããã®ãã¡ãŒã å šäœã¯çžäºã«ãªã³ã¯ãããŠããããªã³ã¯ããã»ã¹ã¯ïŒãã¡ããããªãŒãã³ãœãŒã¹æšæºã«ãã£ãŠïŒææžåãããŠããŸãã
ãããã£ãŠãäžèšã«åºã¥ããŠãã¿ã¹ã¯ã次ã®ããã«èª¬æã§ããŸãïŒã«ãŒã¿ãŒããŒããããã©ãã£ãã¯ã®ã³ããŒãååŸããSuricataã«è»¢éããSuricataããJSON圢åŒã§ããŒã¿ãåä¿¡ããFilebeatã«è»¢éããŸãã KibanaãèŠèŠçãªãã£ã¹ãã¬ã€ãäœæããã®ãå©ããŸããã
Mikrotik RouterOS
Mikrotikã«ãŒã¿ãŒããŒããŠã§ã¢ãããã°ãããŒããã©ãŒãªã³ã°ïŒããŒããã©ãŒãªã³ã°ïŒã®åé¡ã¯ãŸã£ãããããŸããã ãã¹ãŠã¯ãå€éšã€ã³ã¿ãŒãã§ã€ã¹ãééãããã©ãã£ãã¯ãMikrotikèªäœã®ç©ºãããŒãã«ãã©ââãŒãªã³ã°ã§ããããã«ããããšã§æ±ºå®ãããŸãã Mikrotikã«ç©ºãããŒãããªãå Žåã¯ãã¹ã€ããã§ããŒããã©ãŒãªã³ã°ãæå¹ã«ã§ããŸãã ããããç§ã®å ŽåãMikrotikã«ã¯ç©çããŒãããŸã£ãããªããã¹ã€ããã®ããŒãã¯ãã¹ãå šäœãããã©ãã£ãã¯ãåä¿¡ããŸããããã¹ãã«ã¯ãMikrotikã®ä»ã«ãããã«ããã€ãã®ä»®æ³ãã·ã³ããããŸããã
ãããŠãããäžåºŠãå¿ããèšã£ãïŒãããããšãããã¯ããã£ãã¯ïŒãã RouterOSã®çµã¿èŸŒã¿ã¹ããã¡ãŒãããããšãã åŸæ¥ãã¹ã¯ãªãŒã³ã·ã§ããã¯äœ¿çšãããã³ã³ãœãŒã«ã³ãã³ãã®ã¿ã䜿çšããŠããŸããã
WinBoxã§ã¿ãŒããã«ãéããã¹ããã¡ãŒããªã³ã«ããŸãã
/tool sniffer set filter-interface=if-out filter-stream=yes streaming-enabled=yes streaming-server=192.168.1.253
/tool sniffer start
if-outã®ä»£ããã«ããã©ãã£ãã¯ãã€ã³ã¿ãŒã»ããããäºå®ã®ã€ã³ã¿ãŒãã§ãŒã¹ã®ååãããã³192.168.1.253ã®ä»£ããã«-ã€ã³ã¿ãŒã»ããããããã©ãã£ãã¯ãTZSPçµç±ã§éä¿¡ããããã·ã³ã®IPã¢ãã¬ã¹ã瀺ããŸãã
ãã¹ãŠMikrotik'omã§ã
ãããã
äžè¬çã«ãç§ã¯ããŸãLinuxã«åããŠããªãã®ã§ãããããã£ã¹ããªãã¥ãŒã·ã§ã³ã奜ãã§ãã ãŸããããããç§ã¯ããçŠæ¬²çãªDebianã奜ãã§ãã ã ããç§ã¯ããããå§ããŸããã ãã¡ãããLinux以å€ã®åé¡ã®ããã«ããªããžããªãããã€ããªãã€ã³ã¹ããŒã«ãããã£ãã®ã§ãã ã¢ã»ã³ããªã¯ç§ã«ãšã£ãŠåžžã«æ ãè ã§ãã ãããã£ãŠãDebianãéžæããæ©äŒãããå Žåã¯ãéžæããªãã§ãã ãã ã Debianã§ãã¡ãŒã å šäœãã€ã³ã¹ããŒã«ãããã©ã°ã€ã³ãã©ãã«ãã£ãã®ãæ£ç¢ºã«ã¯èŠããŠããŸãããã圌ã¯ããã§ããã ãããŠããã¹ãŠãUbuntaã®äžã«ã€ã³ã¹ããŒã«ããããšã«ã€ããŠã®å šäœçãªã¹ããŒãªãŒã
4 ã®ã¬ãã€ãã®RAMãæã€4ã³ã¢ä»®æ³ãã·ã³ãäœæããã Ubuntu Server 18.04.1 LTSïŒx64ïŒãããŠã³ããŒããããŠã€ã³ã¹ããŒã«ãããŸãã
åæ ïŒä»¥éã®ãã¹ãŠã®ã¢ã¯ã·ã§ã³ã¯ã¹ãŒããŒãŠãŒã¶ãŒã«ä»£ãã£ãŠå®è¡ããããããrootãšããŠãã°ã€ã³ããããåã³ãã³ãã«sudoãè¿œå ããŸãã
å段éã§ã¹ãããã·ã§ãããäœæãããããã«ç¹°ãè¿ãããŒã«ããã¯ãããããæçµçã«ã¯ãä»®æ³ãã·ã³ã®ãªã¢ã«ã¿ã€ã ã§ã®åæããããç¶æ ã§å€ãã®ã°ãªãããçºçãããŸããã
ãããã£ãŠãæ£ããã¿ã€ã ãŸãŒã³ãšNTPåæãããã«èšå®ããŸãã
systemctl start systemd-timesyncd
systemctl status systemd-timesyncd
dpkg-reconfigure tzdata
Suricataã®ã€ã³ã¹ããŒã«æã«äŸåé¢ä¿ã®åé¡ããªãããšã確èªããã«ã¯ã ãŠãããŒã¹ãªããžããªã/etc/apt/sources.listã«è¿œå ããŸãã
nano /etc/apt/sources.list
...
deb archive.ubuntu.com/ubuntuãã€ãªããã¯ã¡ã€ã³ãŠãããŒã¹
deb archive.ubuntu.com/ubuntuãã€ãªããã¯ã»ãã¥ãªãã£ã¡ã€ã³ãŠãããŒã¹
deb archive.ubuntu.com/ubuntu bionic-updatesã¡ã€ã³ãŠãããŒã¹
SuricataãååŸãããªããžããªãè¿œå ããŸãã
add-apt-repository ppa:oisf/suricata-stable
ããã±ãŒãžããŒã¿ããŒã¹ã®æŽæ°ïŒ
apt-get update
Suricataãã€ã³ã¹ããŒã«ããŸãã
apt-get install -y suricata
次ã®ã¹ãããã§ã¯ãSuricataã®ã«ãŒã«ãšãã®æŽæ°ãèšå®ããŸãã
apt-get install -y python-pip
pip install pyyaml
pip install https://github.com/OISF/suricata-update/archive/master.zip
suricata-updateèªäœã®æŽæ°ãéå§ããŸã ã
pip install --pre --upgrade suricata-update
è¿œå ã®æ§æãªãã§å®è¡ãããšãEmerging Threats Openã«ãŒã«ã»ãããæäŸãããŸãã
suricata-update
ãœãŒã¹ã®ãªã¹ãã衚瀺ããã«ã¯ã次ãå®è¡ããŸãã
suricata-update list-sources
ã«ãŒã«ãœãŒã¹ã®æŽæ°ïŒ
suricata-update update-sources
ãœãŒã¹ã§ããã§æŽæ°ãããå 容ã確èªããŠãããäžåºŠå®è¡ããŸãã
suricata-update list-sources
ãã¹ãŠã®ç¡æãœãŒã¹ãå«ãŸããŸãã
suricata-update enable-source ptresearch/attackdetection
suricata-update enable-source oisf/trafficid
suricata-update enable-source sslbl/ssl-fp-blacklist
ãããŠåã³ãã«ãŒã«ãæŽæ°ããŸãã
suricata-update
Suricataãã€ã³ã¹ããŒã«ãããŸãã
次ã«ããã©ãã£ãã¯ãååŸããå¿ èŠããããŸãã
ãã©ã
Trafrã¯ãTZSPãã©ãã£ãã¯ãpcapã«å€æããããã«Mikrotikã«ãã£ãŠäœæãããã¢ããªã±ãŒã·ã§ã³ã§ãã ã¢ããªã±ãŒã·ã§ã³ã¯32ããããªã®ã§ãèµ·åããã«ã¯ã64ãããUbuntaã§32ãããã¢ããªã±ãŒã·ã§ã³ã®ãµããŒããæå¹ã«ããå¿ èŠããããŸãã
dpkg --add-architecture i386
apt-get update && apt-get install -y libc6:i386
trafrãããŠã³ããŒãããŠè§£åããŸã ã
wget http://www.mikrotik.com/download/trafr.tgz
tar xzf trafr.tgz
ãã©ãã£ãã¯ããã£ãããããŠããããšã確èªããŸãã
./trafr -s
ãã®ãããªèµ·ååŸãã°ã©ãã£ãã¯ã¢ãŒãã®ã·ã³ããªãã¯åºåãä»®æ³ãã·ã³ã®ã³ã³ãœãŒã«ã§å£ãããããåèµ·åããå¿ èŠããããŸããã sshãä»ããŠPuTTYã«ãªã¢ãŒãæ¥ç¶ããéã«åé¡ã¯ãããŸããã§ããã
ç»é¢ã«ã©ã³ãã ãªã¡ãã€ããèŠãããå Žåããã©ãã£ãã¯ãå°çãã trafrãããããã£ããããŸãã ãã®å Žåã trafrãæ°žäœå°ã«è»¢éãããã€ãã©ã€ã³ãä»ããŠããã«Suricataã«ãã£ããããããã©ãã£ãã¯ãéä¿¡ããŠå®è¡ããŸãã
mv trafr /usr/local/bin/
/usr/local/bin/trafr -s | suricata -c /etc/suricata/suricata.yaml -r /dev/stdin
ããã§ããã©ãã£ãã¯ãã¹ãªã«ã¿ã«å°çããããšã確èªããŸãããã®ããã«ãé£æ¥ç«¯æ«ã§æ¬¡ã®ããšãè¡ããŸãã
tail -f /var/log/suricata/fast.log
æå³ã®ããããã¹ãã®ã¹ããŒãã¹ã¯ããŒã«-ããŒã¢ãã£ãããã©ãã£ãã¯ã®åä¿¡ãã°ã衚瀺ãããŸãã
ãŸããSuricataã®ãã©ãã£ãã¯ãåä¿¡ããã ãã§ãªããåæããããšã確èªããã®ãé¢åã§ã¯ãããŸããã
tail -f /var/log/suricata/eve.json
ããã¯ãFilebeatã«ãã£ãŒãããJSON圢åŒã®Suricataããã®ã€ãã³ãã®åºåã§ãã
Elasticsearch + Filebeat + Kibana 6.5
Elasticãªããžããªã䜿çšããããã«å¿ èŠãªPGPããŒãã€ã³ã¹ããŒã«ããå¿ èŠãªäŸåé¢ä¿ãã€ã³ã¹ããŒã«ããŸãã
wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo apt-key add -
echo "deb https://artifacts.elastic.co/packages/6.x/apt stable main" | sudo tee -a /etc/apt/sources.list.d/elastic-6.x.list
apt-get update && apt-get install -y openjdk-8-jre apt-transport-https wget nginx
Javaã¯ããŒãžã§ã³8ã§ãã8ãè¶ ãããã®ã¯ãµããŒããããŠããŸããã ãããã£ãŠãããæ°ããJavaã以åã«ã€ã³ã¹ããŒã«ã§ããå Žåã¯ããããç Žæ£ããŠ8ã眮ããŸãã
Javaãæ£ããã€ã³ã¹ããŒã«ãããŠããããšã確èªããŸãã
java -version
ããã次ã®çµè«ãåŸãããŸãã
JavaããŒãžã§ã³ "1.8.0_191"
JavaïŒTMïŒSEã©ã³ã¿ã€ã ç°å¢ïŒãã«ã1.8.0_191-b12ïŒ
Java HotSpotïŒTMïŒ64ããããµãŒããŒVMïŒãã«ã25.191-b12ãæ··åã¢ãŒãïŒ
Kibanaã«ã¢ã¯ã»ã¹ããããã®ãŠãŒã¶ãŒãšãã¹ã¯ãŒããäœæããŸãã 管çè ã®ä»£ããã«ãã奜ã¿ã®ãã®ãéžæããŠãã ããã
echo "admin:`openssl passwd -apr1`" | sudo tee -a /etc/nginx/htpasswd.users
ELKã¯localhostã§ã¹ãã³ãããããnginxã§ãªããŒã¹ãããã·ãæ§æããŸãã
nano /etc/nginx/sites-available/kibana
ãµãŒããŒ{
80ãèããŸãã
server_name suricata.server;
auth_basicãã¢ã¯ã»ã¹å¶éã;
auth_basic_user_file /etc/nginx/htpasswd.users;
å Žæ/ {
proxy_pass localhost ïŒ5601;
proxy_http_version 1.1;
proxy_set_header Upgrade $ http_upgrade;
proxy_set_headeræ¥ç¶ 'ã¢ããã°ã¬ãŒã';
proxy_set_header Host $ host;
proxy_cache_bypass $ http_upgrade;
}
}
rm /etc/nginx/sites-enabled/default
ln -s /etc/nginx/sites-available/kibana /etc/nginx/sites-enabled/kibana
nginxãåèµ·åããŸãã
systemctl restart nginx
Elasticsearchã眮ããŸãïŒ
apt-get install -y elasticsearch
OSã®ããŒãæã«èªåå®è¡ããªã³ã«ããŸãã
systemctl daemon-reload
systemctl enable elasticsearch.service
以äžãéå§ããŸãã
systemctl start elasticsearch.service
äžæããŠãããã©ããã確èªããŸãã
curl -X GET "localhost:9200/"
ããŒããŠã§ã¢ã®ããã©ãŒãã³ã¹ã«ãã£ãŠã¯ãESã®èµ·åã«æéããããå ŽåããããŸãã æ¥ç¶ãæåŠãããå Žåããªã¯ãšã¹ããç¹°ãè¿ãã次ã®ãããªãã®ãåŸããããŸã§åŸ ã¡ãŸãã
{
ãååãïŒãlcZuxxmãã
ãCluster_nameãïŒãelasticsearchãã
ãCluster_uuidãïŒãkmJHqJnlQe2Rk7F-CRi4EAãã
ãããŒãžã§ã³ãïŒ{
ãçªå·ãïŒã6.5.1ãã
ãBuild_flavorãïŒãããã©ã«ããã
ãBuild_typeãïŒãdebãã
ãBuild_hashãïŒã8c58350ãã
ããã«ãæ¥ãïŒã2018-11-16T02ïŒ22ïŒ42.182257Zãã
ãBuild_snapshotãïŒfalseã
ãLucene_versionãïŒã7.5.0ãã
"Minimum_wire_compatibility_version"ïŒ "5.6.0"ã
ãMinimum_index_compatibility_versionãïŒã5.0.0ã
}ã
ãã£ãããã¬ãŒãºïŒç¥ã£ãŠãããæ€çŽ¢çš
}
Kibanaãé 眮ããŸãã
apt-get install -y kibana
OSã®ããŒãæã«èªåå®è¡ããªã³ã«ããŸãã
systemctl daemon-reload
systemctl enable kibana.service
以äžãéå§ããŸãã
systemctl start kibana.service
ããã§192.168.1.253ã«ç§»åã§ããŸãïŒãã¡ãããIPã¢ãã¬ã¹ã¯ããŒã¢ãã£ããã§ãã·ã³ã«å²ãåœãŠããããã®ã§ãïŒã Kibanaã«ããŒããŒãžãéããŸãã
Filebeatãé 眮ããŸãã
apt-get install -y filebeat
OSã®ããŒãæã«èªåå®è¡ããªã³ã«ããŸãã
systemctl daemon-reload
systemctl enable filebeat
Filebeatã¢ãžã¥ãŒã«ã»ããã®äžéšã§ããSuricataã¢ãžã¥ãŒã«ããªã³ã«ããŸãã
filebeat modules enable suricata
Elasticsearchã§Suricataã®ãã©ã°ã€ã³ãã€ã³ã¹ããŒã«ããïŒ
/usr/share/elasticsearch/bin/elasticsearch-plugin install ingest-geoip
/usr/share/elasticsearch/bin/elasticsearch-plugin install ingest-user-agent
2019幎5æ22æ¥ã®UPDãã芧ãã ããã
Elasticsearchã®åèµ·åïŒ
systemctl restart elasticsearch.service
Filebeatã®åææ§æãå®è¡ãããšåæã«ãKibanaã«ãã³ãã¬ãŒããããŒãããŸãã
filebeat setup -e
Filebeatã/var/log/suricata/eve.jsonãèŠã€ããŠåŠçããŠããããšã確èªããŸããããè¡ãã«ã¯ã å ¬éããŒã«ãŒã䜿çšããŠããŒã¿åºåã¢ãŒãã§Filebeatãå®è¡ããŸãã
filebeat -e -d "publish"
æåã¯Filebeatèªäœã®json圢åŒã®åºåã次ã«ãã®ãã°ã®åçŽãªããã¹ãåºåã§ããã°ããããŠããSuricataããã®åºåã§ãããã¹ãŠãæ©èœããããšã確èªããŠãã ããã ãã®åŸãFilebeatãäžæ¢ããŠbashã«æ»ããŸãã
OSã®ããŒãæã«èªåå®è¡ããªã³ã«ããŸãã
systemctl daemon-reload
systemctl enable filebeat.service
Filebeatãå®è¡ããŸãã
systemctl start filebeat.service
Kibanaã«ç§»åããå·ŠåŽã®ã¡ãã¥ãŒãã[ããã·ã¥ããŒã]ãéžæãã filebeat- * indexãéžæããŸãã ããã·ã¥ããŒããããäžåºŠéžæãããªã¹ããã[Suricata]ã¢ã©ãŒãã®æŠèŠãéžæãããšã次ã®ããã«ãªããŸãã
ãªãã·ã§ãã«
ãã°ããŒããŒã·ã§ã³ãå¿ããªãã§ãã ãããããŒããã©ã€ãã®å®¹éã«é¢ä¿ãªããSuricataã¯éåžžã«è¿ éã«ã¹ã³ã¢ãèšé²ããŸãã
nano /etc/logrotate.d/suricata
/var/log/suricata/*.log /var/log/suricata/*.json
{
æ¯é±
å転3
è¡æ¹äžæ
å§çž®ããªã
äœæãã
å ±æã¹ã¯ãªãã
åŸå転
/ bin / kill -HUP `cat /var/run/suricata.pid 2> / dev / null` 2> / dev / null || æ¬åœ
çµãã
}
å ããŠã誰ãããã¯ããã£ãã¯ã§å®æçã«ã¹ããã¡ãŒãå®è¡ããŠãããšããåããããŸããã 次ã«ãã¹ããã¡ãŒãåèµ·åããã¹ã±ãžã¥ãŒã«ã«åŸã£ãŠå®è¡ããã¹ã¯ãªãããäœæããŸãã
/tool sniffer stop
:delay 30s
/tool sniffer start
ãããã«
ççŽã«èšã£ãŠãç§ã¯äžèšã®ãã³ãã«ã®å®å®æ§ã«å®å šã«ã¯æºè¶³ããŠããŸããã ã€ãŸããåèµ·åãã䟡å€ããããå¥è·¡ãå§ãŸããŸãã äžåºŠããã¢ãé€ããã¹ãŠã®ã«ãŒã«ãã«ãŒã«ã®åŠçãåæ¢ããŸããã ãã¹ãŠãåã€ã³ã¹ããŒã«ããå¿ èŠããããŸããã 2åç®ã«ãElasticsearchã¯äžè¬ã«Filebeatããã®ããŒã¿ã®åä¿¡ãåæ¢ããåèµ·åããåã«ç¶æ ã®ã¹ãããã·ã§ããã«ããŒã«ããã¯ããå¿ èŠããããŸããã
ãããã®åé¡ã¯ãŸã 解決ããŠããŸããã
ããã«ãMikrotikã«è²æž¡ãããSuricataã«ãã£ãŠç¹å®ãããæªåœ¹ã®IPã¢ãã¬ã¹ã«åºã¥ããŠIPSãå®è£ ããèšç»ããããŸãã
UPD ïŒäžå®å®æ§ã®åçºã¯åé€ãããŸããã ã«ãŒã«åŠçã®çµäºã«é¢ããç§ã®çµè«ã¯èª€ãã§ããã å®éãåèµ·ååŸã«ããã·ã¥ããŒãã空ã«ãªãçç±ã¯ãFilebeatãšElasticsearchãmeerkatãããã«ãã®ã¬ãã€ãã®jsonãã¡ã€ã«ã解æããã®ã«ããªãã®æéãèŠãããšããäºå®ã«ãããã®ã§ãã eve.jsonãã¡ã€ã«ãäœæãããæ¥ä»ãå«ãæéã®ã€ãã³ãã§ããã·ã¥ããŒããéããšããã¡ã€ã«ãåŠçãããã«ã€ããŠã°ã©ãã®åãã©ã®ããã«æé·ãããã確èªã§ããŸãã åŠçãããã€ãã³ããšãšãã«ãã¢ã©ãŒãã察å¿ããããã·ã¥ããŒãã«è¡šç€ºãããŸãã ããã«ãx86äžã®RouterOSã®ã¹ããã¡ãŒã¯ãã³ã°ããŸããã§ããã
UPD 2019幎5æ22æ¥ ïŒããŒãžã§ã³Elasticsearch 6.7以éãingest-geoipããã³ingest-user-agentãã©ã°ã€ã³ã¯ã¢ãžã¥ãŒã«ã«å€æãããŸããã ãããã£ãŠãã€ã³ã¹ããŒã«ãããã¢ã€ãã ã¯ã¹ããããããŸãã
ãŸããã¢ããã°ã¬ãŒããããšãElasticsearchã®èµ·åãšã©ãŒãçºçããŸãã ãã°ã«ãšã©ãŒã衚瀺ãããŸãïŒ
[/ etc / elasticsearch / ingest-geoip]ã«ååšããªããšäºæ³ãããããŒã¿ããŒã¹[GeoLite2-ASN.mmdb]
ããã©ãŒãã³ã¹ãå埩ããã«ã¯ã次ãå®è¡ããŸãã
/usr/share/elasticsearch/bin/elasticsearch-plugin remove --purge ingest-geoip