ELK Server Configuration

  1. Download and install Elasticsearch, Logstash, and Kibana as outlined on the https://www.elastic.co/products website.
  2. Edit the /etc/elasticsearch/elasticsearch.yml file.
  3. Give the cluster.name a unique name.
  4. Enter the service elasticsearch start command.
  5. Configure services to run on boot using these commands:
    • chkconfig --add elasticsearch (adds it as a service)
    • chkconfig --add logstash (adds it as a service)
    • chkconfig elasticsearch (tells the service to auto-run at boot level 3, 5, and 6)
    • on (tells the service to auto-run at boot level 3, 5, and 6)
  6. Enter the service logstash start command.
  7. Enter the httpd restart command.
  8. Enter the iptables -A INPUT -p tcp -m tcp --dport 9200 -j ACCEPT command.