Skip to content

Feat: Setup ELK Stack for Honeypot Log Collection#32

Open
IV-cmd wants to merge 15 commits intoc2siorg:mainfrom
IV-cmd:feat-elk-logging
Open

Feat: Setup ELK Stack for Honeypot Log Collection#32
IV-cmd wants to merge 15 commits intoc2siorg:mainfrom
IV-cmd:feat-elk-logging

Conversation

@IV-cmd
Copy link
Copy Markdown

@IV-cmd IV-cmd commented Mar 30, 2026

Implements Issue #18

Changes

  • Elasticsearch: Single-node cluster with optimized memory
  • Logstash: JSON parsing with GeoIP enrichment
  • Kibana: Real-time attack visualization
  • Filebeat: Log shipping from honeypot VMs

Verification to be performed

  • Logs appear in Kibana within 30 seconds
  • GeoIP shows attacker locations
  • Dashboard displays attack patterns

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant