Visualizing with Kibana
Josh Stroschein
Security Researcher
@jstrosch [Link]
Once data is in Elasticsearch, we need to
Overview operationalize it
- Kibana provides powerful visualization
capabilities
Install and configure Kibana
Begin creating visualizations and
dashboards
Setting up the Final Component
Elasticsearch Logstash Kibana
Data storage, index Receive, transform Visualizing and
and search and ship log data searching
Provides the ability to create interactive
visualizations
- Easy to explore data and get different
perspectives
While some features are premium, there is a
significant amount of free capabilities
- Visualization options such as maps,
histograms, pie charts and more
Explore your data, build visualizations then
combine into custom dashboards
- Easy to share
- Can find many pre-built dashboards
Sample Dashboard With Web Server Data
Geolocation
from IP
Visitors by
Requested
operating
content size
system
Visitor count
Demo Install Kibana in our Linux server
- Install from .deb package
Ensure necessary configuration changes
are made to view Elasticsearch data
Access Kibana and create an initial index
pattern