### Installation Note For Elastic Stack 7.x SIEM ###


SIEM ===> Security information and event management

===> Production must 3 nodes Elastic.

  - node01
  - node02
  - node03

===> For single node (demo and development)

discovery.type: single-node

Default installation without SSL between nodes in cluster
Must configure security

Easier way ==> copy the same pk12 to all nodes.

Remember to generate default system username and your own strong password
I will c***e you if not using more than 8 characters alpha numering special characters and such, password.
And change password every 30 days Please.....

*** Monitoring Setting For Elastic Stack 7.x ***


===> elasticsearch.yml

xpack.monitoring.enabled: true
xpack.monitoring.collection.enabled: true

===> kibana.yml

xpack.monitoring.enabled: true
xpack.monitoring.kibana.collection.enabled: true
xpack.monitoring.ui.enabled: true

===> logstash.yml

xpack.monitoring.enabled: true
xpack.monitoring.elasticsearch.hosts: ["http://localhost:9200"]
xpack.monitoring.elasticsearch.sniffing: true
xpack.monitoring.collection.pipeline.details.enabled: true

=== *** ===

*** Beats Installation Simple Note ***


apt install filebeat
apt install metricbeat
apt install auditbeat
apt install packetbeat
apt install heartbeat-elastic

===> don't install heartbeat package. Its other software not from elastic

# ==> Make sure all beats xml configuration files, upload dashboard using kibana is done first time only or after upgrade
# ===>
# These settings control loading the sample dashboards to the Kibana index. Loading
# the dashboards is disabled by default and can be enabled either by setting the
# options here or by using the `setup` command.
setup.dashboards.enabled: true

==> Done the above before proceed to run the beats. Only once at any one node of a cluster. And repeat again for every upgrade.

filebeat modules enable system iptables elasticsearch auditd kibana logstash

metricbeat modules enable system elasticsearch kibana logstash docker kubernetes logstash-xpack kibana-xpack elasticsearch-xpack

===> for other beats edit inside each config xml. For heartbeat need to edit xml files inside monitor.d

systemctl enable filebeat
systemctl enable metricbeat
systemctl enable auditbeat
systemctl enable packetbeat
systemctl enable heartbeat-elastic

systemctl restart filebeat
systemctl restart metricbeat
systemctl restart auditbeat
systemctl restart packetbeat
systemctl restart heartbeat-elastic

### Harisfazillah Jamel 09092019 : linuxmalaysia @ gmail dot com ### Blue Team

