Visualize your logs¶
Make sure you have logs being sent to your HELK first (At least Windows security and Sysmon events). Then, go to
https://<HELK's IP> in your preferred browser. If you don’t see logs right away then update your time picker (in the top right) to include a farther back window. Additionally, if you just started sending logs then wait a minute and check again.
Currently, HELK creates automatically 7 index patterns for you and sets logs-endpoint-winevent-sysmon-* as your default one:
Currently, the HELK comes with 3 dashboards:
Monitoring Views (x-Pack Basic Free License)¶
Kibana Initial Overview¶
Apart from running
docker ps and
docker logs --follow --tail 25 helk-kibana, additionally you can look at logs located at
docker exec helk-kibana tail -f /usr/share/kibana/config/kibana_logs.log
Many times Kibana will not be “working” because elasticsearch is still starting up or has ran into an error.