Mikrotik Network Logs + Elastic Stack (Elastic, Kibana, and Filebeat)

preview_player
Показать описание
How to do a basic installation of the Elastic Stack and export network logs from a Mikrotik router.

If you found this tutorial helpful, Please share, like, comment, or subscribe!

-----------------------------------------------------------------------------------------------------------------------------------------------------------------

Рекомендации по теме
Комментарии
Автор

Realy thanks for this video, please show how to compress data and storage in aws and rotate indexes. Great work!

JeanFredson
Автор

great and educative video, you saved me a ton of research. God bless you

efokafui
Автор

excelent video!, does it work for cisco routers?, thanks!

mariodiaz
Автор

thank you very much, for your tutorial!
I have succeeded from X try: current version of kibana/elasticsearch did not work for me.
had to install specific versions ( apt install kibana=7.15.2, etc )

thing that bothers me in the these trafficflow logs/reports is that local network addresses are not translated and in the end I have statistics
of conversations between my router and final host (say google/youtube) instead of conversations between media server and google/youtube.
but maybe my mikrotik is misconfigured somehow, need to dig more.

dormoose
Автор

Thank you. May I ask you how you run the docker image. Do you have to set any volume to preserve the data or to indicate any port? Can you indicate the line to run the ubuntu docker image?

pastoralopez
Автор

do i have to change the filebeat input

kieno
Автор

"Module status" to check Filebeat module In Kibana. says "No data has been received from this module yet" Any ideas why filebeat not showing any logs in Kibana?

GoogleReviewer
Автор

Is filebeat mandatory? I've been trying to make it work without installing it, but kibana doesnt show any data....

rocchirodrigo
Автор

Many thanks for the excellent video. Great work, keep it up! Sub earnt

riley
Автор

Hello Everyone,

After upgrading to Router OS version 7 I noticed that the Netflow export was not working and some people on the forums have also experienced the same issue. The setting default is to leave the "source ip" field blank in Traffic Flow Target. I have found a workaround which is to put the WAN IP address typically assigned to the interface ethr1 in source ip. This config has got netflow export to work again.

Ravis_Computers