Files required on Server and Clients to install ELK Stack for NXLog Windows Event collection
1. Configure WEF server and clients
-there are plenty of tutorials on this and it's fairly straightforward
-you will be done once your systems are forwarding specified logs to a collector
2. Configure an ELK system to receive events -use the following tutorial exactly
--make sure you use Ubuntu 14.04 and follow instructions provided
-https://www.devopslibrary.com/lessons/elk-stack-for-logging-tutorial
**2a. Reconfigure ELK system for specific events from WEF system**
-use elasticsearch.yml, kibana.yml, and logstash.conf files in this repo
--MAKE SURE TO SWAP THE SERVER IP WITH YOUR ELK SERVER IP ADDRESS
-tweaked the configuration files according to this site:
--https://nxlog.co/docs/elasticsearch-kibana/using-nxlog-with-elasticsearch-and-kibana.html
3. Configure WEF collector system to send ForwardedEvents to ELK system
-use the nxlog.conf file in this repo
--MAKE SURE TO SWAP THE SERVER IP WITH YOUR ELK SERVER IP ADDRESS