--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/acf66687-62dc-42a0-ae48-a03cefff69fan%40googlegroups.com.




On 10 May 2021, at 17:51, Rafael Antonio Rodriguez Otero <rafaell.ro...@gmail.com> wrote:
take easy, there are no stupid questions but stupid ones that don't ask. hehehehe.
First, tell me what version of Wazuh and ELK system do you have?
You have to do these steps correctly.
https://documentation.wazuh.com/current/installation-guide/more-installation-alternatives/elastic-stack/distributed-deployment/step-by-step-installation/kibana/
Then in the kibana panel look for the wazuh plugins app.
When you finish the installation you will be able to see the dashboards.
El lun, 10 de may. de 2021 a la(s) 03:07, Mauro Tridici (mauro....@cmcc.it) escribió:
Hi Rafael,thank you very much for your answer.I installed WAZUH using the all-in-one unattended installation.I noticed that WAZUH has its dashboards for each agent, but I can see also that there is a Kibana section (in the left navigation bar) that should/could be configured to have an overview of main (cumulative) statistics.
<Screenshot 2021-05-10 at 09.03.05.png>

On 10 May 2021, at 22:44, Rafael Antonio Rodriguez Otero <rafaell.ro...@gmail.com> wrote:
my translator mistranslates me hehehe. again.1.) enter the visualizations plugin in kibana.
El lun, 10 de may. de 2021 a la(s) 16:44, Rafael Antonio Rodriguez Otero (rafaell.ro...@gmail.com) escribió:
Sorry.1.) enter aircraft displays.1.) entra en el plugin de visualizaciones en kibana.my translator mistranslates me hehehe.
El lun, 10 de may. de 2021 a la(s) 14:47, Rafael Antonio Rodriguez Otero (rafaell.ro...@gmail.com) escribió:
Good to make you an example, more specific, you must do the following:
1.) enter aircraft displays.
2.) select the wazuh alert indices.
3.) enter coordinate point display.
4.) select the GeoLocarion.Location field where within the GeoHash aggregation (this may vary depending on the wazuh template).
5.) Put in the filter the criteria you need. (If you do not put any criteria, it will show you all the geo points of all the criteria that the template has, in my case they appear, do not place any criteria.)<Captura de pantalla_2021-05-10_14-40-33.png>
where it says "search", under share or insecpt or refresh. There the criterion or filter is placed.
El lun, 10 de may. de 2021 a la(s) 14:32, Rafael Antonio Rodriguez Otero (rafaell.ro...@gmail.com) escribió:
remember.
You have to review the fields that you are going to use for the map. You can check it in the template that is created in elasticsearch for the wazuh indexes. I believe that this template already has the configuration of some fields with GEO IP, those fields are the ones that are accepted in the map.
You tell me anything. Do not worry.
El lun, 10 de may. de 2021 a la(s) 14:25, Rafael Antonio Rodriguez Otero (rafaell.ro...@gmail.com) escribió:
Well. To do GEO-IP you have to show me the data that you are accumulating, that is, you must have public IP addresses.
Of course you have to create custom dashboards, but you must know how to do it, first you must create visualizations and then in bashboard you have to join your visualizations.
But in the case of creating a map where an activity appears by public IP addresses, you have to create the visualization with the criteria you need. This already depends on your criteria. if it is due to authentication failures or if it is due to VPN connections.
https://www.elastic.co/es/blog/geoip-in-the-elastic-stack
You can use this document, it is in Spanish, but you can translate it.
El lun, 10 de may. de 2021 a la(s) 13:19, Mauro Tridici (mauro....@cmcc.it) escribió:
Hello Rafael,many thanks for your patience.I recently installed Wazuh v.4.1 (latest available version).I installed everything using the ALL-IN-ONE unattended-installation -> https://documentation.wazuh.com/current/installation-guide/open-distro/all-in-one-deployment/unattended-installation.htmlI checked all the steps and everything seems to be up & running.As you can see from the screenshot below, Agents dashboards are ok in the "Wazuh section"Unfortunately, I’m not able to create the Kibana Dashboards in the “Kibana section” (I’m referring to “Create your first dashboard” page)I’m only struggling about the last point 😊I’m looking for some cumulative (and already existing) Kibana Dashboards with GeoIp Statistics (for example) and some main “summary” statistics in order to have a centralised view of what it’s happening.Thank you in advance,Mauro
<Screenshot 2021-05-10 at 19.10.57.png><Screenshot 2021-05-10 at 18.59.50.png><Screenshot 2021-05-10 at 18.59.29.png>