{"repo":"H21lab/tsharkVM","free":true,"listed":false,"github":"https://github.com/H21lab/tsharkVM","clone":"git clone https://github.com/H21lab/tsharkVM.git","description":"tshark + ELK analytics virtual machine","language":"Shell","stars":68,"topics":["tshark","wireshark","vm","elk","kibana","logstash","elasticsearch","virtual-machine","tshark-vm","ndjson"],"license":"Apache-2.0","category":"analytics","readme_excerpt":"💡 Update: tshark-opensearch More recent application tshark-opensearch is now available. You can find it in the https://github.com/h21-lab/apps-collection-info repository. 👉 Get Access tshark ELK VM appliance This project builds virtual machine which can be used for analytics of tshark -T ek (ndjson) output. The virtual appliance is built using vagrant, which builds Debian with pre-installed and pre-configured ELK stack. After the VM is up, the process is simple: decoded pcaps ( tshark -T ek output / ndjson) are sent over TCP/17570 to the VM ELK stack in VM will process and index the data Kibana is running in VM and can be accessed on http://127.0.0.1:15601/app/kibana#/dashboards Instuctions to build VM from Ubuntu desktop Clone source code Build tshark VM Upload pcaps to VM Open Kibana with browser Open Main Dashboard and increase time window to e.g. last 100 years to see there the sample pcaps. SSH to VM Delete VM Start VM Stop VM SSH into VM and check if ELK is running correctly Elasticsearch mapping template In the project is included simple Elasticsearch mapping template generated for the frame,eth,ip,udp,tcp,dhcp protocols. To handle additional protocols efficiently it can be required to update the mapping template in the following way: Alternative can be using the dynamic mapping. See template ./Kibana/template tshark mapping dynamic.json . And consider setting the numeric detection parameter true/false depending on the mapping requirements and pcaps used. Upload the ","default_branch":null,"files":null,"tree":[],"storefront":"/r/H21lab","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/H21lab/tsharkVM/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}