Follow this step by step guide to get 'logs' from your system to Logit.io:
Step 1 - Setup Syslog Output
On your Cynet web interface, go to Settings > Advanced.
Check the box next to Send Audit Records to SIEM.
Go to Configuration > SIEM settings
Select UDP in the Protocol menu.
Enter the IP address of your remote syslog server into the Syslog host field. This is your Filebeat Server.
Enter the port number. (Make sure to update the Filebeat Configuration if using a customer port)
Select Add. The added IP and port will be visible on screen.
Step 3 - Configure Filebeat.yml
The configuration file below is pre-configured to send data to your Logit.io Stack.
Copy the configuration file below and overwrite the contents of the Filebeat configuration file typically located at
# ============================== Filebeat inputs =============================== filebeat.inputs: - type: udp max_message_size: 10MiB host: "0.0.0.0:514" enabled: true fields: type: fields_under_root: true encoding: utf-8 ignore_older: 12h # ================================== Outputs =================================== output.logstash: hosts: ["your-logstash-host:your-ssl-port"] loadbalance: true ssl.enabled: true
If you’re running Filebeat 7, add this code block to the end. Otherwise, you can leave it out.
# ... For Filebeat 7 only ... filebeat.registry.path: /var/lib/filebeat
If you’re running Filebeat 6, add this code block to the end.
# ... For Filebeat 6 only ... registry_file: /var/lib/filebeat/registry
It’s a good idea to run the configuration file through a YAML validator to rule out indentation errors, clean up extra characters, and check if your YAML file is valid. Yamllint.com is a great choice.
Step 4 - Start filebeat
Start or restart to apply the configuration changes.
Step 5 - Check Logit.io for your logs
Now you should view your data:
If you don't see logs take a look at How to diagnose no data in Stack below for how to diagnose common issues.