ELK integration

This article outlines the custom content developed by Vectra for ELK (Elastic, Logstash and Kibana) when using Vectra Stream. This content can be integrated with your ELK deployment.

Introduction

A primary function of the Vectra AI Platform is its ability to provide Enhanced Network Metadataarrow-up-right gathered from various network sensors deployed across an environment. This metadata can be managed by Vectra (when using Vectra Recall) or stored in any Data Lake (when using Vectra Stream). A common choice for hosting this data is the ELK Stack (Elasticsearch, Logstash and Kibana). This article provides various resources for setting up and utilizing the network metadata produced by Vectra.

Compatibility matrix

​​​​​Qualified version of ELK:

  • 7.x

  • 8.x

ELK 7.x
ELK 8.x

[Logstash] config samples

Yes

Yes

[Elasticsearch] Index templates

Yes

Yes*

[Elasticsearch]Component Templates

Yes*

[Kibana] Index patterns

Yes

[Kibana] Data View

Yes

[Kibana] Searches

Yes

Yes

[Kibana] Visualizations & Dashboards

Yes

Yes

* Composable index templates have been introduced in Elasticsearch 7.8.

Content Library

This content is stored in a GitHub repository. This is available at this address https://github.com/vectranetworks/vectra-content-for-elkarrow-up-right.

Hosting this content on GitHub, as opposed to directly in this knowledge base, presents several advantages:

  • Simplified change tracking

  • Efficient version control

  • Bug reporting capabilities

  • Option to submit enhancement requests

  • Notifications for any updates or changes.

The READMEarrow-up-right file in the GitHub repository contains all the information about the content available as well as the instructions to install it.

In a nutshell, it contains the following:

You might not be utilizing Logstash for log shipping. While it has long been a favored choice and remains extensively used, other alternatives like Fluentdarrow-up-right have become increasingly popular. It's important to note that the content for Elasticsearch and Kibana remains consistent regardless of the log shipper you use. Additionally, Vectra Stream offers support for directly sending network metadata to Elasticsearch.

Support

If you believe you found a bug or have an idea you'd like to suggest you may report an issuearrow-up-right or start a discussionarrow-up-right.

Last updated

Was this helpful?