Start your 14-day free trial today

No Credit Card Required

Try Logit.io Free

Already have an account? Sign In

Send data via Cynet to your Logstash instance provided by Logit.io

Cynet

Ship Cynet logs to logstash

Step 1 - Setup Syslog OutputCopy

On your Cynet web interface, go to Settings > Advanced.

Check the box next to Send Audit Records to SIEM.

Go to Configuration > SIEM settings

Select UDP in the Protocol menu.

Enter the IP address of your remote syslog server into the Syslog host field. This is your Filebeat Server.

Enter the port number. (Make sure to update the Filebeat Configuration if using a customer port)

Select Add. The added IP and port will be visible on screen.

Step 2 - Install FilebeatCopy

To get started first follow the steps below:

  • Install
  • Root access
  • Verify the required port is open

Older versions can be found here 7, 6, 5

Step 3 - Configure Filebeat.ymlCopy

The configuration file below is pre-configured to send data to your Logit.io Stack.

Copy the configuration file below and overwrite the contents of the Filebeat configuration file typically located at /etc/filebeat/filebeat.yml

# ============================== Filebeat inputs ===============================
filebeat.inputs:

- type: udp
  max_message_size: 10MiB
  host: "0.0.0.0:514"
  enabled: true

  fields:
     type: 
  fields_under_root: true
  encoding: utf-8
  ignore_older: 12h

# ================================== Outputs ===================================
output.logstash:
    hosts: ["your-logstash-host:your-ssl-port"]
    loadbalance: true
    ssl.enabled: true

If you’re running Filebeat 7, add this code block to the end. Otherwise, you can leave it out.

# ... For Filebeat 7 only ...
filebeat.registry.path: /var/lib/filebeat

If you’re running Filebeat 6, add this code block to the end.

# ... For Filebeat 6 only ...
registry_file: /var/lib/filebeat/registry

It’s a good idea to run the configuration file through a YAML validator to rule out indentation errors, clean up extra characters, and check if your YAML file is valid. Yamllint.com is a great choice.

Step 4 - Start filebeatCopy

Start or restart to apply the configuration changes.

Step 5 - Check Logit.io for your logsCopy

Now you should view your logs:

Launch Dashboard

If you don't see logs take a look at How to diagnose no data in Stack below for how to diagnose common issues.

Step 6 - how to diagnose no data in StackCopy

If you don't see data appearing in your Stack after following the steps, visit the Help Centre guide for steps to diagnose no data appearing in your Stack or Chat to support now.

Toggle View

Compact View

Return to Search

© 2023 Logit.io Ltd, All rights reserved.