<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ELK | RobWillis.info</title>
	<atom:link href="/tag/elk/feed/" rel="self" type="application/rss+xml" />
	<link>/</link>
	<description>#yolosec</description>
	<lastBuildDate>Mon, 27 Jun 2022 04:04:52 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9</generator>
	<item>
		<title>Everything You Need To Know To Get Started Logging PowerShell</title>
		<link>/2019/10/everything-you-need-to-know-to-get-started-logging-powershell/</link>
		
		<dc:creator><![CDATA[robwillisinfo]]></dc:creator>
		<pubDate>Mon, 07 Oct 2019 00:15:30 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[Pen Testing]]></category>
		<category><![CDATA[PowerShell/Scripting]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Servers]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[4103]]></category>
		<category><![CDATA[4104]]></category>
		<category><![CDATA[Downgrade Attacks]]></category>
		<category><![CDATA[ELK]]></category>
		<category><![CDATA[Get-PSEventLogSize]]></category>
		<category><![CDATA[GPO]]></category>
		<category><![CDATA[Group Policy]]></category>
		<category><![CDATA[Module]]></category>
		<category><![CDATA[Obfuscated]]></category>
		<category><![CDATA[Powershell]]></category>
		<category><![CDATA[Restricted]]></category>
		<category><![CDATA[Script block]]></category>
		<category><![CDATA[SD]]></category>
		<category><![CDATA[Security Descriptor]]></category>
		<category><![CDATA[Tool]]></category>
		<category><![CDATA[Transcription]]></category>
		<guid isPermaLink="false">/?p=4432</guid>

					<description><![CDATA[<p>Intro Recently, I have been spending a lot of time researching and working with PowerShell logging. Since PowerShell is readily available (built-in to the OS) and has an assortment of functionality that can be used across the entire kill chain right out of the box, it is an ideal candidate for virtually any type of [&#8230;]</p>
The post <a href="/2019/10/everything-you-need-to-know-to-get-started-logging-powershell/">Everything You Need To Know To Get Started Logging PowerShell</a> first appeared on <a href="/">RobWillis.info</a>.]]></description>
		
		
		
			</item>
		<item>
		<title>Gathering Windows, PowerShell and Sysmon Events with Winlogbeat &#8211; ELK 7 &#8211; Windows Server 2016 (Part II)</title>
		<link>/2019/05/gathering-windows-powershell-and-sysmon-events-with-winlogbeat-elk-7-windows-server-2016/</link>
		
		<dc:creator><![CDATA[robwillisinfo]]></dc:creator>
		<pubDate>Tue, 07 May 2019 02:43:19 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[PowerShell/Scripting]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Servers]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[2016]]></category>
		<category><![CDATA[Elasticsearch]]></category>
		<category><![CDATA[ELK]]></category>
		<category><![CDATA[Kibana]]></category>
		<category><![CDATA[Logs]]></category>
		<category><![CDATA[Logstash]]></category>
		<category><![CDATA[Powershell]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[Sysmon]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Winlogbeat]]></category>
		<guid isPermaLink="false">/?p=4162</guid>

					<description><![CDATA[<p>In part I of this series, Installing ELK 7 (Elasticsearch, Logstash and Kibana) on Windows Server 2016, I covered the following: Installing and configuring Elasticsearch, Logstash, and Kibana as Windows services Installing and configuring Winlogbeat to forward logs from the ELK server into ELK Installing and configuring Curator as a scheduled task (optional) Now, in [&#8230;]</p>
The post <a href="/2019/05/gathering-windows-powershell-and-sysmon-events-with-winlogbeat-elk-7-windows-server-2016/">Gathering Windows, PowerShell and Sysmon Events with Winlogbeat – ELK 7 – Windows Server 2016 (Part II)</a> first appeared on <a href="/">RobWillis.info</a>.]]></description>
		
		
		
			</item>
		<item>
		<title>Installing ELK 7 (Elasticsearch, Logstash and Kibana) &#8211; Windows Server 2016 (Part I)</title>
		<link>/2019/05/installing-elk-7-elasticsearch-logstash-and-kibana-windows-server-2016/</link>
		
		<dc:creator><![CDATA[robwillisinfo]]></dc:creator>
		<pubDate>Tue, 07 May 2019 02:42:55 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[Pen Testing]]></category>
		<category><![CDATA[PowerShell/Scripting]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Servers]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[2016]]></category>
		<category><![CDATA[Elasticsearch]]></category>
		<category><![CDATA[ELK]]></category>
		<category><![CDATA[Kibana]]></category>
		<category><![CDATA[Logs]]></category>
		<category><![CDATA[Logstash]]></category>
		<category><![CDATA[Powershell]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[Sysmon]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Winlogbeat]]></category>
		<guid isPermaLink="false">/?p=4058</guid>

					<description><![CDATA[<p>I am a huge fan of the Elastic stack as it can provide a great deal of visibility into even the largest of environments, which can help enable both engineering and security teams rapidly triage technical issues or incidents at scale. There&#8217;s also the fact that unlike Splunk, the Elastic software is free to use [&#8230;]</p>
The post <a href="/2019/05/installing-elk-7-elasticsearch-logstash-and-kibana-windows-server-2016/">Installing ELK 7 (Elasticsearch, Logstash and Kibana) – Windows Server 2016 (Part I)</a> first appeared on <a href="/">RobWillis.info</a>.]]></description>
		
		
		
			</item>
		<item>
		<title>Home Lab Cooling Upgrade!</title>
		<link>/2018/10/home-lab-cooling-upgrade/</link>
		
		<dc:creator><![CDATA[robwillisinfo]]></dc:creator>
		<pubDate>Mon, 29 Oct 2018 03:24:14 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[Servers]]></category>
		<category><![CDATA[Cooling]]></category>
		<category><![CDATA[Elastic]]></category>
		<category><![CDATA[ELK]]></category>
		<category><![CDATA[ESXi]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[FreeBSD]]></category>
		<category><![CDATA[Home Lab]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[nginx]]></category>
		<category><![CDATA[OPNsense]]></category>
		<category><![CDATA[pfSense]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[snort]]></category>
		<category><![CDATA[VMWare]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">/?p=3979</guid>

					<description><![CDATA[<p>In this video I show off my latest project &#8211; Upgrading the cooling system on my home lab in hopes of making it a little more efficient while quieting things down a bit. The original setup consisted of the following: 2 x 6&#8243; Ducts with Fans 6&#8243; Flexible Ducting Originally there was just a single [&#8230;]</p>
The post <a href="/2018/10/home-lab-cooling-upgrade/">Home Lab Cooling Upgrade!</a> first appeared on <a href="/">RobWillis.info</a>.]]></description>
		
		
		
			</item>
		<item>
		<title>Home Lab Setup (2017)</title>
		<link>/2018/02/home-lab-setup/</link>
		
		<dc:creator><![CDATA[robwillisinfo]]></dc:creator>
		<pubDate>Sun, 04 Feb 2018 15:51:15 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[Pen Testing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Servers]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[blue]]></category>
		<category><![CDATA[Elastic]]></category>
		<category><![CDATA[ELK]]></category>
		<category><![CDATA[ESXi]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[FreeBSD]]></category>
		<category><![CDATA[Home Lab]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[nginx]]></category>
		<category><![CDATA[OPNsense]]></category>
		<category><![CDATA[pfSense]]></category>
		<category><![CDATA[red]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[snort]]></category>
		<category><![CDATA[team]]></category>
		<category><![CDATA[VMWare]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">/?p=3508</guid>

					<description><![CDATA[<p>In this post and video I give a quick run down of my Home Lab &#8211; everything from the rack itself, to the hardware and the basics of what everything is being used for. I started this project towards the end of 2012 with a single Dell PowerEdge 2950 GII and was hoping to teach [&#8230;]</p>
The post <a href="/2018/02/home-lab-setup/">Home Lab Setup (2017)</a> first appeared on <a href="/">RobWillis.info</a>.]]></description>
		
		
		
			</item>
		<item>
		<title>ELK Stack &#8211; Installing and Configuring Curator</title>
		<link>/2017/11/elk-stack-installing-and-configuring-curator/</link>
		
		<dc:creator><![CDATA[robwillisinfo]]></dc:creator>
		<pubDate>Thu, 16 Nov 2017 15:42:29 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Servers]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[Curator]]></category>
		<category><![CDATA[Elastic]]></category>
		<category><![CDATA[Elasticsearch]]></category>
		<category><![CDATA[ELK]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[Kibana]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Logs]]></category>
		<category><![CDATA[Logstash]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">/?p=3462</guid>

					<description><![CDATA[<p>In this post I am going to quickly cover what is needed to get Curator up and running on the ELK stack. In the last few posts about the ELK stack I covered everything needed to get it installed, configured and ingesting logs reliably. If you missed those posts, you can find them here: ELK [&#8230;]</p>
The post <a href="/2017/11/elk-stack-installing-and-configuring-curator/">ELK Stack – Installing and Configuring Curator</a> first appeared on <a href="/">RobWillis.info</a>.]]></description>
		
		
		
			</item>
		<item>
		<title>ELK Stack &#8211; Tips, Tricks and Troubleshooting</title>
		<link>/2017/11/elk-stack-tips-tricks-and-troubleshooting/</link>
		
		<dc:creator><![CDATA[robwillisinfo]]></dc:creator>
		<pubDate>Fri, 10 Nov 2017 02:55:43 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[Servers]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[Elastic]]></category>
		<category><![CDATA[Elasticsearch]]></category>
		<category><![CDATA[ELK]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[Kibana]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Logs]]></category>
		<category><![CDATA[Logstash]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">/?p=3394</guid>

					<description><![CDATA[<p>This post is going to be a sort of a follow up to my ELK 5 on Ubuntu 16.04 series. I am going to cover some of the lessons I have learned over the last few months of maintaining a running ELK stack instance. I am also going to cover some one liners that can [&#8230;]</p>
The post <a href="/2017/11/elk-stack-tips-tricks-and-troubleshooting/">ELK Stack – Tips, Tricks and Troubleshooting</a> first appeared on <a href="/">RobWillis.info</a>.]]></description>
		
		
		
			</item>
		<item>
		<title>ELK 5: Setting up a Grok filter for IIS Logs</title>
		<link>/2017/05/elk-5-setting-up-a-grok-filter-for-iis-logs/</link>
		
		<dc:creator><![CDATA[robwillisinfo]]></dc:creator>
		<pubDate>Thu, 11 May 2017 14:47:05 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Servers]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[Elastic]]></category>
		<category><![CDATA[Elasticsearch]]></category>
		<category><![CDATA[ELK]]></category>
		<category><![CDATA[Grok]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[Kibana]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Logs]]></category>
		<category><![CDATA[Logstash]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">/?p=3171</guid>

					<description><![CDATA[<p>In Pt. 3 of my setting up ELK 5 on Ubuntu 16.04 series, I showed how easy it was to ship IIS logs from a Windows Server 2012 R2 using Filebeat. One thing you may have noticed with that configuration is that the logs aren&#8217;t parsed out by Logstash, each line from the IIS log [&#8230;]</p>
The post <a href="/2017/05/elk-5-setting-up-a-grok-filter-for-iis-logs/">ELK 5: Setting up a Grok filter for IIS Logs</a> first appeared on <a href="/">RobWillis.info</a>.]]></description>
		
		
		
			</item>
		<item>
		<title>ELK 5 on Ubuntu 16.04</title>
		<link>/2017/04/elk-5-on-ubuntu-16-04/</link>
		
		<dc:creator><![CDATA[robwillisinfo]]></dc:creator>
		<pubDate>Fri, 21 Apr 2017 04:02:27 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Servers]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[Elastic]]></category>
		<category><![CDATA[Elasticsearch]]></category>
		<category><![CDATA[ELK]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[Kibana]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Logs]]></category>
		<category><![CDATA[Logstash]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">/?p=3137</guid>

					<description><![CDATA[<p>In this series of posts I am going to cover everything needed to get Elasticsearch, Logstash and Kibana (ELK) up and running on Ubuntu 16.04. In the videos I use the desktop version of Ubuntu, but the process should be the same on the server version. In addition to the ELK stack I will also [&#8230;]</p>
The post <a href="/2017/04/elk-5-on-ubuntu-16-04/">ELK 5 on Ubuntu 16.04</a> first appeared on <a href="/">RobWillis.info</a>.]]></description>
		
		
		
			</item>
		<item>
		<title>ELK 5 on Ubuntu: Pt. 3 &#8211; Installing and Configuring Beats Agents on Windows Clients</title>
		<link>/2017/04/elk-5-on-ubuntu-pt-3-installing-and-configuring-beats-agents-on-windows-clients/</link>
		
		<dc:creator><![CDATA[robwillisinfo]]></dc:creator>
		<pubDate>Fri, 21 Apr 2017 03:41:39 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[PowerShell/Scripting]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Servers]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[Elastic]]></category>
		<category><![CDATA[Elasticsearch]]></category>
		<category><![CDATA[ELK]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[Kibana]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Logs]]></category>
		<category><![CDATA[Logstash]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">/?p=3108</guid>

					<description><![CDATA[<p>In the previous two posts I went over everything from installing Ubuntu to getting the ELK stack setup and ingesting logs from itself. Now in this final post in the series I am going to cover collecting Windows Event and IIS logs from remote Windows clients. Here is the quick run down of exactly what [&#8230;]</p>
The post <a href="/2017/04/elk-5-on-ubuntu-pt-3-installing-and-configuring-beats-agents-on-windows-clients/">ELK 5 on Ubuntu: Pt. 3 – Installing and Configuring Beats Agents on Windows Clients</a> first appeared on <a href="/">RobWillis.info</a>.]]></description>
		
		
		
			</item>
	</channel>
</rss>
