{"id":40905,"date":"2023-04-15T10:40:40","date_gmt":"2023-08-15T02:46:57","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e6%83%b3%e8%a6%81%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8bwowhoneypot%e7%9a%84%e6%97%a5%e5%bf%97%e3%80%82\/"},"modified":"2024-04-29T23:38:01","modified_gmt":"2024-04-29T15:38:01","slug":"%e6%88%91%e6%83%b3%e8%a6%81%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8bwowhoneypot%e7%9a%84%e6%97%a5%e5%bf%97%e3%80%82","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e6%83%b3%e8%a6%81%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8bwowhoneypot%e7%9a%84%e6%97%a5%e5%bf%97%e3%80%82\/","title":{"rendered":"\u6211\u60f3\u8981\u5728Kibana\u4e0a\u67e5\u770bWOWHoneypot\u7684\u65e5\u5fd7"},"content":{"rendered":"<p>\u6211\u60f3\u5c1d\u8bd5\u4f7f\u7528WOWHoneypot\u6765\u8bbe\u7f6e\u871c\u7f50\u3002<\/p>\n<p>WOWHoneypot: \u4e3a\u521d\u5b66\u8005\u63d0\u4f9b\uff01\u6b22\u8fce\u653b\u51fb\u8005\u7684 Web \u871c\u7f50<\/p>\n<p>\u7531\u4e8e\u9700\u8981\u68c0\u67e5\u670d\u52a1\u5668\u8bbf\u95ee\u65e5\u5fd7\uff0c\u5e76\u4e14\u90e8\u5206\u65e5\u5fd7\u91c7\u7528Base64\u7f16\u7801\uff0c\u56e0\u6b64\u6211\u4eec\u51b3\u5b9a\u4f7f\u7528Kibana\u8fdb\u884c\u53ef\u89c6\u5316\u3002<\/p>\n<p>\u8bf7\u8c05\u89e3\uff0c\u5c3d\u7ba1\u6211\u7684\u81ea\u8eab\u7ecf\u9a8c\u6709\u9650\uff0c\u6709\u4e9b\u65b9\u9762\u8fd8\u4e0d\u591f\u6210\u719f\uff0c\u4f46\u8bf7\u5bbd\u5bb9\u4ee5\u5f85\u2026<\/p>\n<h1>\u524d\u63d0 t\u00ed)<\/h1>\n<p>\u672c\u6b21\u6211\u9009\u62e9\u5148\u5728VMware\u4e0a\u6784\u5efa\uff0c\u7136\u540e\u518d\u8fc1\u79fb\u5230AWS\u7684\u8fc7\u7a0b\u3002\u4e0b\u9762\u53ea\u8bb0\u5f55VMware\u4e0a\u7684\u6784\u5efa\u90e8\u5206\u3002<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">OS: Centos7\u7cfb<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u30e1\u30e2\u30ea2GB, \u30d7\u30ed\u30bb\u30c3\u30b52\u63a8\u5968<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">NAT\u8a2d\u5b9a\u3082\u304a\u5fd8\u308c\u306a\u304f<\/ul>\n<div><\/div>\n<h1>\u51c6\u5907\u5de5\u4f5c<\/h1>\n<div><\/div>\n<h2>\u5b89\u88c5<\/h2>\n<p>\u5b89\u88c5Git\u548cPython3<br \/>\n\u53ef\u9009\u62e9\u5b89\u88c5Vim<\/p>\n<pre class=\"post-pre\"><code>$ yum -y install git\u200b\r\n$ yum -y install python3\r\n$ yum -y install vim\r\n<\/code><\/pre>\n<div><\/div>\n<h2>\u9632\u706b\u5899\u8bbe\u7f6e<\/h2>\n<p>\u6211\u4f1a\u6253\u5f008080\u30015601\u548c9200\u7aef\u53e3\u3002<\/p>\n<pre class=\"post-pre\"><code># firewall-cmd --zone=public --add-port=8080\/tcp --permanent\r\n# firewall-cmd --zone=public --add-port=5601\/tcp --permanent\r\n# firewall-cmd --zone=public --add-port=9200\/tcp --permanent\r\n# firewall-cmd --reload\r\n<\/code><\/pre>\n<p>\u63a5\u4e0b\u6765\uff0c\u5c06\u7aef\u53e3\u53f7\u4ece80\u8f6c\u53d1\u52308080\uff08\u867d\u7136\u4e0d\u662f\u7edd\u5bf9\u5fc5\u8981\u7684\uff0c\u4f46\u4ece\u6d4f\u89c8\u5668\u8bbf\u95ee\u65f6\u4f1a\u66f4\u4e3a\u4fbf\u6377\uff09\u3002<\/p>\n<p>\u5f53\u7528\u6237\u8bbf\u95ee80\u53f7\u7aef\u53e3\u65f6\uff0c\u8bf7\u8bbe\u7f6e\u4e3a\u8df3\u8f6c\u52308080\u7aef\u53e3\u3002<\/p>\n<pre class=\"post-pre\"><code># firewall-cmd --add-forward-port=port=80:proto=tcp:toport=8080 --permanent\r\n# firewall-cmd --reload\r\n<\/code><\/pre>\n<div><\/div>\n<h1>\u5b89\u88c5\u7684\u4e1c\u897f de xi)<\/h1>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">WOWHoneypot<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Fluentd (td-agent)<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">elastic search<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">kibana<\/ul>\n<h1>\u6784\u6210\u5f62\u8c61<\/h1>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d439337434c4406c9c844\/24-0.png\" alt=\"architecture.png\" \/><\/div>\n<div><\/div>\n<h1>\u54c7\u5594\u871c\u7f50<\/h1>\n<h2>WOWHoneypot\u662f\u4ec0\u4e48\uff1f<\/h2>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u653b\u6483\u8005\u3092\u304a\u3082\u3066\u306a\u3057\u3059\u308b Web \u30cf\u30cb\u30fc\u30dd\u30c3\u30c8<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\u9001\u4fe1\u5143\u304b\u3089\u306e HTTP \u30ea\u30af\u30a8\u30b9\u30c8\u3092\u305d\u306e\u307e\u307e\u4fdd\u5b58\u3059\u308b\u306e\u3067\u3001\u200b\u5f8c\u304b\u3089\u3058\u3063\u304f\u308a\u3086\u3063\u304f\u308a\u30ed\u30b0\u5206\u6790\u3092\u3059\u308b\u3053\u3068\u304c\u53ef\u80fd<\/ul>\n<p>Github: https:\/\/github.com\/morihisa\/WOWHoneypot<\/p>\n<div><\/div>\n<h2>WOWHoneypot \u5b89\u88c5\u6307\u5357<\/h2>\n<p>\u53ea\u9700\u8981\u4ecegit\u514b\u9686\u5373\u53ef<br \/>\n\u4f8b\u5982\uff1a\u5c06\u514b\u9686\u653e\u5728\/opt\/\u76ee\u5f55\u4e0b\u7684\u6b65\u9aa4<\/p>\n<pre class=\"post-pre\"><code>$ cd \/opt\/\r\n$ git clone https:\/\/github.com\/morihisa\/WOWHoneypot\u200b\r\n<\/code><\/pre>\n<div><\/div>\n<p>\u5982\u679copt\u6587\u4ef6\u5939\u4e0b\u5b58\u5728&#8221;WOWHoneypot&#8221;\uff0c\u5c31\u6ca1\u95ee\u9898\u3002<\/p>\n<h2>WOWHoneypot \u5f00\u542f\u786e\u8ba4<\/h2>\n<p>\u542f\u52a8\u300cwowhoneypot.py\u300d<\/p>\n<pre class=\"post-pre\"><code>$ cd \/opt\/WOWHoneypot\r\n$ python3 .\/wowhoneypot.py\r\n<\/code><\/pre>\n<div><\/div>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d439337434c4406c9c844\/40-0.png\" alt=\"wowstart.png\" \/><\/div>\n<p>\u5728\u6b64\u4e4b\u540e\uff0c\u8bbf\u95eehttp:\/\/&#8221;ip\u5730\u5740&#8221;<br \/>\n\u82e5\u51fa\u73b0\u5982\u4e0b\u6240\u793a\u7684\u5c4f\u5e55\uff0c\u5219\u8868\u793a\u64cd\u4f5c\u6210\u529f\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d439337434c4406c9c844\/42-0.png\" alt=\"wowhttp.png\" \/><\/div>\n<p>\u5982\u679c\u60a8\u60f3\u7528\u80cc\u5305\u78e8\u5e8a\u79fb\u52a8\uff0c\u8bf7\u53c2\u8003\u4ee5\u4e0b\u7f51\u7ad9\uff1ahttps:\/\/qiita.com\/hogehuga\/items\/cad931485f58ae487d53\u3002<\/p>\n<div><\/div>\n<h2>\u786e\u8ba4WOWHoneypot\u7684\u8bbf\u95ee\u65e5\u5fd7<\/h2>\n<p>\u5f53\u901a\u8fc7\u6d4f\u89c8\u5668\u8bbf\u95ee\u65f6\uff0c\u4f1a\u5411\u201caccess_log\u201d\u5199\u5165\u65e5\u5fd7\u3002<\/p>\n<pre class=\"post-pre\"><code>$ tail \/opt\/WOWHoneypot\/log\/access_log\r\n<\/code><\/pre>\n<div><\/div>\n<p>\u7136\u540e\uff0c\u901a\u8fc7\u4f7f\u7528Fluentd\u63d2\u4ef6\uff0c\u6211\u4eec\u53ef\u4ee5\u540c\u65f6\u8fdb\u884c\u89e3\u7801\u5e76\u5c06\u5176\u4f20\u8f93\u5230elasticsearch\uff0c\u56e0\u6b64\u6211\u4eec\u5c06\u8fdb\u884c\u76f8\u5e94\u7684\u8bbe\u7f6e\u3002<\/p>\n<div><\/div>\n<h1>\u6d41\u5229\u7684<\/h1>\n<h2>\u6d41\u7545\u65e5\u5fd7(Fluentd\u6216td-agent) \u662f\u4ec0\u4e48\uff1f<\/h2>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d439337434c4406c9c844\/53-0.png\" alt=\"fluentdimg.png\" \/><\/div>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u30c7\u30fc\u30bf\u53ce\u96c6\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u4e3b\u306bRuby\u3067\u69cb\u6210\u3055\u308c\u3066\u3044\u308b<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\u4eca\u56de\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u300ctd-agent\u300d\u306f\u3001Fluentd\u306e\u5b89\u5b9a\u7248\u200b<\/ul>\n<div><\/div>\n<h2>\u90e8\u7f72 Fluentd \u7684\u6b65\u9aa4<\/h2>\n<p>\u8f93\u5165\u4ee5\u4e0b\u547d\u4ee4\uff0c\u6267\u884cyum<\/p>\n<pre class=\"post-pre\"><code># curl -L https:\/\/toolbelt.treasuredata.com\/sh\/install-redhat-td-agent3.sh | sh\r\n\r\n\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u305f\u304b\u78ba\u8a8d\r\n# yum list | grep td-agent\r\ntd-agent.x86_64  3.8.1-0.el7  @treasuredata\r\n<\/code><\/pre>\n<div><\/div>\n<h2>\u5b89\u88c5Fluentd\u63d2\u4ef6\u3002<\/h2>\n<p>\u5b89\u88c5\u63d2\u4ef6\u4ee5\u5c06\u65e5\u5fd7\u4f20\u9001\u5230Elasticsearch\u5e76\u89e3\u7801base64\u3002<br \/>\n\u5b89\u88c5td-agent\u540e\uff0c\u5c06\u6709\u4e00\u4e2a\u540d\u4e3a&#8221;td-agent-gem&#8221;\u7684\u547d\u4ee4\u53ef\u7528\uff0c\u4f7f\u7528\u8be5\u547d\u4ee4\u8fdb\u884c\u5b89\u88c5\u3002<\/p>\n<div><\/div>\n<p>\u7528\u4e8e\u67e5\u627e\u63d2\u4ef6\u7684\u7f51\u7ad9<\/p>\n<div><\/div>\n<pre class=\"post-pre\"><code># td-agent-gem install elasticsearch\r\n# td-agent-gem install fluent-plugin-filter-base64-decode\r\n<\/code><\/pre>\n<div><\/div>\n<h2>\u786e\u8ba4 Fluentd \u662f\u5426\u5df2\u542f\u52a8\u3002<\/h2>\n<p>\u7528systemctl\u542f\u52a8<\/p>\n<pre class=\"post-pre\"><code># systemctl start td-agent\r\n# systemctl enable td-agent\r\n\r\nactive\u306b\u306a\u3063\u3066\u3044\u308c\u3070\u6210\u529f\r\n# systemctl status td-agent\r\n<\/code><\/pre>\n<div><\/div>\n<h1>Elasticsearch\u4e0ekibana<\/h1>\n<h2>Elasticsearch \u662f\u4ec0\u4e48<\/h2>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d439337434c4406c9c844\/73-0.png\" alt=\"elasticimg.png\" \/><\/div>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u5206\u6563\u691c\u7d22\/\u5206\u6790\u30a8\u30f3\u30b8\u30f3<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\u30ed\u30b0\u5206\u6790\u3001\u30d5\u30eb\u30c6\u30ad\u30b9\u30c8\u691c\u7d22\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u3001\u30d3\u30b8\u30cd\u30b9\u5206\u6790\u3001\u304a\u3088\u3073\u30aa\u30da\u30ec\u30fc\u30b7\u30e7\u30ca\u30eb\u30a4\u30f3\u30c6\u30ea\u30b8\u30a7\u30f3\u30b9\u306e\u30e6\u30fc\u30b9\u30b1\u30fc\u30b9\u306b\u5e83\u304f\u4f7f\u7528\u3055\u308c\u3066\u3044\u308b<\/ul>\n<div><\/div>\n<h2>Kibana \u662f\u4ec0\u4e48\uff1f<\/h2>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d439337434c4406c9c844\/77-0.png\" alt=\"kibana.png\" \/><\/div>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Elasticsearch\u5c02\u7528\u306e\u30c7\u30fc\u30bf\u8996\u899a\u5316\u30c0\u30c3\u30b7\u30e5\u30dc\u30fc\u30c9\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\u30ed\u30b0\u306e\u53ef\u8996\u5316\u306b\u7528\u3044\u3089\u308c\u308b\u3053\u3068\u304c\u591a\u3044<\/ul>\n<p>\u5f53\u8c08\u5230\u65e5\u5fd7\u53ef\u89c6\u5316\u65f6\uff0cElasticsearch\u548cKibana\u57fa\u672c\u4e0a\u88ab\u8ba4\u4e3a\u662f\u4e00\u5957\uff08\u8fd9\u53ea\u662f\u6211\u7684\u5370\u8c61\uff09\u3002<\/p>\n<div><\/div>\n<h2>Elasticsearch Kibana \u5b89\u88c5\u6b65\u9aa4<\/h2>\n<div><\/div>\n<h3>\u5b89\u88c5Java<\/h3>\n<pre class=\"post-pre\"><code># yum install java-1.8.0-openjdk-devel -y\r\n# java -version\r\nopenjdk version \"1.8.0_312\"\r\nOpenJDK Runtime Environment (build 1.8.0_312-b07)\r\nOpenJDK 64-Bit Server VM (build 25.312-b07, mixed mode)\r\n<\/code><\/pre>\n<div><\/div>\n<h3>\u5b89\u88c5Elasticsearch PGP\u5bc6\u94a5<\/h3>\n<pre class=\"post-pre\"><code># rpm --import https:\/\/artifacts.elastic.co\/GPG-KEY-elasticsearch\r\n<\/code><\/pre>\n<div><\/div>\n<h3>\u6ce8\u518c Elasticsearch \u5b58\u50a8\u5e93<\/h3>\n<pre class=\"post-pre\"><code># vim \/etc\/yum.repos.d\/elasticsearch.repo\r\n\r\n# \u4e0b\u8a18\u3092\u5165\u529b\u3057\u3001\u30d5\u30a1\u30a4\u30eb\u3092\u4fdd\u5b58\r\n[elasticsearch]\r\nname=Elasticsearch repository for 7.x packages\r\nbaseurl=https:\/\/artifacts.elastic.co\/packages\/7.x\/yum\r\ngpgcheck=1\r\ngpgkey=https:\/\/artifacts.elastic.co\/GPG-KEY-elasticsearch\r\nenabled=0\r\nautorefresh=1\r\ntype=rpm-md\r\n<\/code><\/pre>\n<div><\/div>\n<h3>\u5b89\u88c5Elasticsearch Kibana<\/h3>\n<p>\u4e00\u8d77\u5b89\u88c5Kibana\uff08\u9700\u8981\u4e00\u4e9b\u65f6\u95f4\uff09\u3002<\/p>\n<pre class=\"post-pre\"><code># yum install -y --enablerepo=elasticsearch  elasticsearch kibana\r\n<\/code><\/pre>\n<div><\/div>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Kibana\u306b\u5229\u7528\u3059\u308bIP\u30a2\u30c9\u30ec\u30b9\u306e\u8a2d\u5b9a<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\u30b5\u30fc\u30d0\u306b\u5272\u308a\u5f53\u3066\u3089\u308c\u3066\u3044\u308bIP\u30a2\u30c9\u30ec\u30b9\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u3088\u3046\u8a2d\u5b9a<\/ul>\n<pre class=\"post-pre\"><code># vim \/etc\/kibana\/kibana.yml\r\n\r\n\u2193\u3092\u8ffd\u52a0\r\nserver.host: \"0.0.0.0\"\r\n<\/code><\/pre>\n<div><\/div>\n<hr \/>\n<h2>\u786e\u8ba4 Elasticsearch Kibana \u662f\u5426\u542f\u52a8<\/h2>\n<p>\u4f7f\u7528systemctl\u547d\u4ee4\u542f\u52a8\uff0c\u9700\u8981\u4e00\u4e9b\u65f6\u95f4\u3002<\/p>\n<pre class=\"post-pre\"><code># systemctl start elasticsearch kibana\r\n# systemctl enable elasticsearch kibana\r\n<\/code><\/pre>\n<div><\/div>\n<h3>\u4f7f\u7528 Elasticsearch<\/h3>\n<p>\u53ea\u9700\u4ee5\u4ee5\u4e0b\u65b9\u5f0f\u663e\u793a\u5373\u53ef<\/p>\n<div><\/div>\n<pre class=\"post-pre\"><code># curl localhost:9200\r\n\r\n{\r\n  \"name\" : \"localhost.localdomain\",\r\n  \"cluster_name\" : \"elasticsearch\",\r\n  \"cluster_uuid\" : \"CDwf8sbpTfap9zd7CNDaRw\",\r\n  \"version\" : {\r\n    \"number\" : \"7.15.1\",\r\n    \"build_flavor\" : \"default\",\r\n    \"build_type\" : \"rpm\",\r\n    \"build_hash\" : \"83c34f456ae29d60e94d886e455e6a3409bba9ed\",\r\n    \"build_date\" : \"2021-10-07T21:56:19.031608185Z\",\r\n    \"build_snapshot\" : false,\r\n    \"lucene_version\" : \"8.9.0\",\r\n    \"minimum_wire_compatibility_version\" : \"6.8.0\",\r\n    \"minimum_index_compatibility_version\" : \"6.0.0-beta1\"\r\n  },\r\n  \"tagline\" : \"You Know, for Search\"\r\n}\r\n<\/code><\/pre>\n<div><\/div>\n<h3>Kibana \u8bbf\u95ee<\/h3>\n<p>\u8bf7\u8bbf\u95eeIP\u5730\u5740\u4e3a&#8221;IP\u30a2\u30c9\u30ec\u30b9&#8221;\u76845601\u7aef\u53e3\u3002<\/p>\n<p>\u5982\u679c\u51fa\u73b0\u5982\u4e0b\u7684\u753b\u9762\u663e\u793a\uff0c\u90a3\u5c31\u53ef\u4ee5\u4e86\u3002<\/p>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d439337434c4406c9c844\/112-0.png\" alt=\"kibanaAccess.png\" \/><\/div>\n<hr \/>\n<div><\/div>\n<h1>\u5728Kibana\u4e0a\u67e5\u770b8\u4e2a\u65e5\u5fd7<\/h1>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Fluentd\u3067WOWHoneypot\u306e\u30ed\u30b0\u306e\u53d6\u5f97\u30fb\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u30fb\u30c7\u30b3\u30fc\u30c9<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\u53d6\u5f97\u3057\u305f\u30ed\u30b0\u3092Elasticsearch\u3078\u8ee2\u9001<\/ul>\n<p>\u203b\u5047\u8bbeWOWHoneypot\u5df2\u7ecf\u5728opt\u76ee\u5f55\u4e0b\u514b\u9686\uff0c\u5e76\u8fdb\u884c\u4e0b\u4e00\u6b65\u64cd\u4f5c\u3002<\/p>\n<div><\/div>\n<h2>Fluentd\u7684\u914d\u7f6e<\/h2>\n<p>\u586b\u5199\u83b7\u53d6\u65e5\u5fd7\u7684\u914d\u7f6e\u3002<br \/>\n\u7701\u7565\u6b63\u5219\u8868\u8fbe\u5f0f\u7b49\u8be6\u7ec6\u8bf4\u660e\u3002<\/p>\n<pre class=\"post-pre\"><code># vim \/etc\/td-agent\/td-agent.conf\r\n\r\n\u4e0b\u8a18\u306e\u30b3\u30fc\u30c9\u3092\u5f35\u308a\u4ed8\u3051\r\n&lt;source&gt;\r\n  @type tail\r\n  format \/^\\[(?&lt;time&gt;[^\\]]*)\\] (?&lt;clientip&gt;[^ ]*) (?&lt;hostname&gt;[^ ]*) \"(?&lt;method&gt;\\S+)(?: +(?&lt;path&gt;[^ ]*) +\\S*)?\" (?&lt;status&gt;[^ ]*) (?&lt;mrrid&gt;[^ ]*) (?&lt;requestbody&gt;[^ ]*)$\/\r\n  time_format %Y-%m-%d %H:%M:%S%z\r\n  path \/opt\/WOWHoneypot\/log\/access_log\r\n  pos_file \/var\/log\/td-agent\/wowhoneypot.log.pos\r\n  tag wowhoneypot-access\r\n&lt;\/source&gt;\r\n\r\n&lt;filter wowhoneypot-access&gt;\r\n  @type base64_decode\r\n  fields requestbody\r\n&lt;\/filter&gt;\r\n\r\n&lt;match wowhoneypot-access&gt;\r\n  @type elasticsearch\r\n  host localhost\r\n  port 9200\r\n  logstash_format true\r\n&lt;\/match&gt;\r\n\r\n--\u518d\u8d77\u52d5\r\n# systemctl restart td-agent\r\n<\/code><\/pre>\n<div><\/div>\n<h2>\u901a\u8fc7Kibana\u67e5\u770b\u65e5\u5fd7<\/h2>\n<p>\u8bbf\u95ee Kibana\uff0c\u4ece\u4fa7\u8fb9\u680f\u70b9\u51fb\u201cDiscover\u201d\u3002<\/p>\n<div><\/div>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d439337434c4406c9c844\/126-0.png\" alt=\"kibanaDiscover.png\" \/><\/div>\n<p>\u6211\u8ba4\u4e3a\u4f1a\u663e\u793a\u5982\u4e0b\u753b\u9762\uff0c\u8bf7\u70b9\u51fb&#8221;\u521b\u5efa\u7d22\u5f15\u6a21\u5f0f&#8221;\u3002<\/p>\n<div><\/div>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d439337434c4406c9c844\/129-0.png\" alt=\"kibanaIndex.png\" \/><\/div>\n<p>\u5728Name\u6807\u7b7e\u4e2d\u9009\u62e9&#8221;logstash*&#8221;\uff0c\u5728Timestanp\u5b57\u6bb5\u4e2d\u9009\u62e9&#8221;@timestamp&#8221;\uff0c\u7136\u540e\u70b9\u51fb\u53f3\u4e0b\u89d2\u7684&#8221;\u521b\u5efa\u7d22\u5f15\u6a21\u5f0f&#8221;\u3002<\/p>\n<div><\/div>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d439337434c4406c9c844\/132-0.png\" alt=\"kibanaLogstash.png\" \/><\/div>\n<p>\u7a0d\u540e\uff0c\u542f\u52a8WOWHoneypot\uff0c\u5e76\u8fdb\u884c\u51e0\u6b21\u8bbf\u95ee\u4ee5\u83b7\u53d6\u65e5\u5fd7\u8bb0\u5f55\u3002<\/p>\n<p>\u5f53\u60a8\u8bbf\u95eeWOWHoneypot\u540e\uff0c\u7a0d\u7b49\u7247\u523b\uff0c\u5c06\u663e\u793a\u5982\u4e0b\u65e5\u5fd7\u3002<\/p>\n<div><\/div>\n<div><img decoding=\"async\" class=\"post-images\" title=\"\" src=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d439337434c4406c9c844\/136-0.png\" alt=\"kibanaLogs.png\" \/><\/div>\n","protected":false},"excerpt":{"rendered":"<p>\u6211\u60f3\u5c1d\u8bd5\u4f7f\u7528WOWHoneypot\u6765\u8bbe\u7f6e\u871c\u7f50\u3002 WOWHoneypot: \u4e3a\u521d\u5b66\u8005\u63d0\u4f9b\uff01\u6b22\u8fce\u653b\u51fb\u8005\u7684 Web  [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-40905","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u6211\u60f3\u8981\u5728Kibana\u4e0a\u67e5\u770bWOWHoneypot\u7684\u65e5\u5fd7 - Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/\u6211\u60f3\u8981\u5728kibana\u4e0a\u67e5\u770bwowhoneypot\u7684\u65e5\u5fd7\u3002\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u6211\u60f3\u8981\u5728Kibana\u4e0a\u67e5\u770bWOWHoneypot\u7684\u65e5\u5fd7\" \/>\n<meta property=\"og:description\" content=\"\u6211\u60f3\u5c1d\u8bd5\u4f7f\u7528WOWHoneypot\u6765\u8bbe\u7f6e\u871c\u7f50\u3002 WOWHoneypot: \u4e3a\u521d\u5b66\u8005\u63d0\u4f9b\uff01\u6b22\u8fce\u653b\u51fb\u8005\u7684 Web [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/\u6211\u60f3\u8981\u5728kibana\u4e0a\u67e5\u770bwowhoneypot\u7684\u65e5\u5fd7\u3002\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2023-08-15T02:46:57+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-29T15:38:01+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d439337434c4406c9c844\/24-0.png\" \/>\n<meta name=\"author\" content=\"\u6e05, \u626c\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u6e05, \u626c\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e6%83%b3%e8%a6%81%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8bwowhoneypot%e7%9a%84%e6%97%a5%e5%bf%97%e3%80%82\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e6%83%b3%e8%a6%81%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8bwowhoneypot%e7%9a%84%e6%97%a5%e5%bf%97%e3%80%82\/\",\"name\":\"\u6211\u60f3\u8981\u5728Kibana\u4e0a\u67e5\u770bWOWHoneypot\u7684\u65e5\u5fd7 - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2023-08-15T02:46:57+00:00\",\"dateModified\":\"2024-04-29T15:38:01+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/cb5556d2501da73d864cac945e8d9461\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e6%83%b3%e8%a6%81%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8bwowhoneypot%e7%9a%84%e6%97%a5%e5%bf%97%e3%80%82\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e6%83%b3%e8%a6%81%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8bwowhoneypot%e7%9a%84%e6%97%a5%e5%bf%97%e3%80%82\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e6%83%b3%e8%a6%81%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8bwowhoneypot%e7%9a%84%e6%97%a5%e5%bf%97%e3%80%82\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u6211\u60f3\u8981\u5728Kibana\u4e0a\u67e5\u770bWOWHoneypot\u7684\u65e5\u5fd7\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/cb5556d2501da73d864cac945e8d9461\",\"name\":\"\u6e05, \u626c\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/32a4239de8ff29adace466261d309424a1e5fe9f7e3036bf89fe03f2e3dbe717?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/32a4239de8ff29adace466261d309424a1e5fe9f7e3036bf89fe03f2e3dbe717?s=96&d=mm&r=g\",\"caption\":\"\u6e05, \u626c\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/qingyang\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e6%83%b3%e8%a6%81%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8bwowhoneypot%e7%9a%84%e6%97%a5%e5%bf%97%e3%80%82\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u6211\u60f3\u8981\u5728Kibana\u4e0a\u67e5\u770bWOWHoneypot\u7684\u65e5\u5fd7 - Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/\u6211\u60f3\u8981\u5728kibana\u4e0a\u67e5\u770bwowhoneypot\u7684\u65e5\u5fd7\u3002\/","og_locale":"zh_CN","og_type":"article","og_title":"\u6211\u60f3\u8981\u5728Kibana\u4e0a\u67e5\u770bWOWHoneypot\u7684\u65e5\u5fd7","og_description":"\u6211\u60f3\u5c1d\u8bd5\u4f7f\u7528WOWHoneypot\u6765\u8bbe\u7f6e\u871c\u7f50\u3002 WOWHoneypot: \u4e3a\u521d\u5b66\u8005\u63d0\u4f9b\uff01\u6b22\u8fce\u653b\u51fb\u8005\u7684 Web [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/\u6211\u60f3\u8981\u5728kibana\u4e0a\u67e5\u770bwowhoneypot\u7684\u65e5\u5fd7\u3002\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2023-08-15T02:46:57+00:00","article_modified_time":"2024-04-29T15:38:01+00:00","og_image":[{"url":"https:\/\/cdn.silicloud.com\/blog-img\/blog\/img\/657d439337434c4406c9c844\/24-0.png"}],"author":"\u6e05, \u626c","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u6e05, \u626c","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"2 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e6%83%b3%e8%a6%81%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8bwowhoneypot%e7%9a%84%e6%97%a5%e5%bf%97%e3%80%82\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e6%83%b3%e8%a6%81%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8bwowhoneypot%e7%9a%84%e6%97%a5%e5%bf%97%e3%80%82\/","name":"\u6211\u60f3\u8981\u5728Kibana\u4e0a\u67e5\u770bWOWHoneypot\u7684\u65e5\u5fd7 - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2023-08-15T02:46:57+00:00","dateModified":"2024-04-29T15:38:01+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/cb5556d2501da73d864cac945e8d9461"},"breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e6%83%b3%e8%a6%81%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8bwowhoneypot%e7%9a%84%e6%97%a5%e5%bf%97%e3%80%82\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e6%83%b3%e8%a6%81%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8bwowhoneypot%e7%9a%84%e6%97%a5%e5%bf%97%e3%80%82\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e6%83%b3%e8%a6%81%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8bwowhoneypot%e7%9a%84%e6%97%a5%e5%bf%97%e3%80%82\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"\u6211\u60f3\u8981\u5728Kibana\u4e0a\u67e5\u770bWOWHoneypot\u7684\u65e5\u5fd7"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/cb5556d2501da73d864cac945e8d9461","name":"\u6e05, \u626c","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/32a4239de8ff29adace466261d309424a1e5fe9f7e3036bf89fe03f2e3dbe717?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/32a4239de8ff29adace466261d309424a1e5fe9f7e3036bf89fe03f2e3dbe717?s=96&d=mm&r=g","caption":"\u6e05, \u626c"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/qingyang\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/%e6%88%91%e6%83%b3%e8%a6%81%e5%9c%a8kibana%e4%b8%8a%e6%9f%a5%e7%9c%8bwowhoneypot%e7%9a%84%e6%97%a5%e5%bf%97%e3%80%82\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/40905","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=40905"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/40905\/revisions"}],"predecessor-version":[{"id":88336,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/40905\/revisions\/88336"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=40905"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=40905"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=40905"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}