Anyone using splunk and willing to share useful searches

Matthew Newton mcn4 at leicester.ac.uk
Wed Oct 21 15:31:45 CEST 2015


On Wed, Oct 21, 2015 at 03:19:12PM +0200, Michael Schwartzkopff wrote:
> You may give logstash / elasticsearch / kibana a try. If you set up a log 
> monitoring system from the scratch for RADIUS it might just fit you needs.

Cue reminder about the logstash/elasticsearch config files in the
FreeRADIUS source:

https://github.com/FreeRADIUS/freeradius-server/tree/v3.0.x/doc/schemas/logstash

I hope to have a basic Kibana dashboard there soon as well. Open
to suggestions for improvement (e.g. I didn't geocode any of the
IP addresses because it didn't seem worthwhile for our own
wireless network, but now that I'm developing RADIUS for a VPN it
makes more sense so I'll probably add that).

And no licencing fees - we're trying to throw *everything* in it.

Matthew


-- 
Matthew Newton, Ph.D. <mcn4 at le.ac.uk>

Systems Specialist, Infrastructure Services,
I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom

For IT help contact helpdesk extn. 2253, <ithelp at le.ac.uk>


More information about the Freeradius-Users mailing list