Elasticsearch snapshots

Creating Elasticsearch Snapshots

Benjamin Franklin once wrote “…in this world nothing can be said to be certain, except death and taxes”. In this computerized world of ours, I would add having to backup your data to free up disk space to that list of eventualities. For Elasticsearch users, backups are done using the Elasticsearch snapshot facility. In this […]

logstash-ossec

Improved OSSEC Log Parsing with Logstash

The ELK stack (Elasticsearch-Logstash-Kibana) provides a cost effective alternative to commercial SIEMs for ingesting and managing OSSEC alert logs. Previously I wrote a blog – OSSEC Log Management with Elasticsearch – that discusses the design of an ELK based log system. Since then some readers have asked for and suggested ways to parse additional fields […]

Elasticsearch Python

Elasticsearch Client Programming (2/2) – Python

The first article in this two part series focused on developing Elasticsearch clients with Perl. Elasticsearch also has an excellent Python library which lets you search for and analyze your data with one of the many mathematics and machine learning libraries available for Python. In this article I’ll cover how to create an Elasticsearch client […]

Elasticsearch Perl

Elasticsearch Client Programming (1/2) – Perl

Since creating a log management system for the OSSEC HIDS with Elasticsearch, I have been busy applying this useful search technology in other projects. Elasticsearch is a marvelous system for ingesting streaming data that gets indexed on the fly and quickly searching your data. The Elasticsearch community provides client libraries that expose their search API in several […]

Socket Time Out

TCP/IP Sockets with Time Out Capabilities

Recently I had a question from one of my readers about how to close connections on a server when there are no requests received after a certain period of time.  The question was asked with regard to the tcpsockets classes I covered in my blog TCP Network Programming Design Patterns in C++, none of which support […]

1 2 3 4 5 6 8