<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Archives des GrayLOG - CoffeeBreak Info</title>
	<atom:link href="https://coffeebreak.en-images.info/category/applications/graylog/feed/" rel="self" type="application/rss+xml" />
	<link>https://coffeebreak.en-images.info/category/applications/graylog/</link>
	<description>Une petite pause :)</description>
	<lastBuildDate>Fri, 12 Nov 2021 15:46:02 +0000</lastBuildDate>
	<language>fr-FR</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>

<image>
	<url>https://coffeebreak.en-images.info/wp-content/uploads/2021/07/cropped-Tasse_Cafe-scaled-1-32x32.jpg</url>
	<title>Archives des GrayLOG - CoffeeBreak Info</title>
	<link>https://coffeebreak.en-images.info/category/applications/graylog/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>MODOP – Installation Grafana/promotheus pour PROXMOX</title>
		<link>https://coffeebreak.en-images.info/modop-installation-grafana-promotheus-pour-proxmox/</link>
					<comments>https://coffeebreak.en-images.info/modop-installation-grafana-promotheus-pour-proxmox/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Fri, 16 Jul 2021 09:41:10 +0000</pubDate>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[GrayLOG]]></category>
		<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[PROXMOX]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Centos]]></category>
		<category><![CDATA[grafana]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[promotheus]]></category>
		<category><![CDATA[Proxmox]]></category>
		<category><![CDATA[supervision]]></category>
		<category><![CDATA[Système]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=3366</guid>

					<description><![CDATA[<p>Mise en place de la supervision des métriques de l'hyperviseur Proxmox via Grafana et Promotheus.</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-grafana-promotheus-pour-proxmox/">MODOP – Installation Grafana/promotheus pour PROXMOX</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img fetchpriority="high" decoding="async" width="1470" height="404" class="wp-image-3367" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-231.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-231.png 1470w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-231-300x82.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-231-1024x281.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-231-768x211.png 768w" sizes="(max-width: 1470px) 100vw, 1470px" /></p>
<p>La machine sera une Centos7</p>
<h4><span style="text-decoration: underline; color: #000000;"><strong>1°) Spécification machine </strong></span></h4>
<p><strong>Grafana01</strong><br />
IP : <strong>192.168.1.28 (vSwitch vmbr0)</strong><br />
Disque 1 – Système 20Go<br />
RAM 2G</p>
<p><img decoding="async" width="766" height="204" class="wp-image-3368" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-232.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-232.png 766w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-232-300x80.png 300w" sizes="(max-width: 766px) 100vw, 766px" /></p>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;"><strong>2°) Installation de Middleware </strong></span></span></h4>
<pre>[root@grafana01 ~]# <strong><span style="color: #ff0000;">yum update -y &amp;&amp; yum upgrade -y</span></strong>
[root@grafana01 ~]# <span style="color: #ff0000;"><strong>yum install -y htop nmap net-tools wget</strong></span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;"><strong>3°) Suppression du selinux </strong></span></span></h4>
<pre>[root@grafana01 ~]# <strong><span style="color: #ff0000;">sed -i 's/SELINUX=enforcing/SELINUX=disabled/g' /etc/selinux/config</span></strong>
[root@grafana01 ~]# <strong><span style="color: #ff0000;">reboot</span></strong></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;"><strong>4°) Installer ntpd</strong></span></span></h4>
<pre>[root@grafana01 ~]#<strong><span style="color: #ff0000;"> yum install ntp ntpdate ntp-doc -y</span></strong>
[root@grafana01 ~]# <span style="color: #ff0000;"><strong>chkconfig ntpd on</strong></span>
[root@grafana01 ~]# <strong><span style="color: #ff0000;">ntpdate pool.ntp.org</span></strong>
[root@grafana01 ~]#<span style="color: #ff0000;"><strong> systemctl start ntpd</strong></span>
[root@grafana01 ~]# <span style="color: #ff0000;"><strong>timedatectl</strong></span></pre>
<p><img decoding="async" width="664" height="241" class="wp-image-3369" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-233.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-233.png 664w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-233-300x109.png 300w" sizes="(max-width: 664px) 100vw, 664px" /></p>
<h4><span style="text-decoration: underline; color: #000000;"><strong>5°) Désactiver l’IPV6</strong></span></h4>
<pre>[root@node01-gfs ]# <strong><span style="color: #ff0000;">vi /etc/sysctl.conf</span></strong>
<span style="color: #ff0000;"><em>net.ipv6.conf.all.disable_ipv6 = 1</em></span>
<span style="color: #ff0000;"><em>net.ipv6.conf.all.autoconf = 0</em></span>
<span style="color: #ff0000;"><em>net.ipv6.conf.default.disable_ipv6 = 1</em></span>
<span style="color: #ff0000;"><em>net.ipv6.conf.default.autoconf = 0</em></span></pre>
<pre>[root@node01-gfs]#<span style="color: #ff0000;"><strong> sysctl -p</strong></span></pre>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;"><strong>6°) Installation Grafana</strong></span></span></h4>
<p><strong>Ajout repository grafana</strong></p>
<pre>[root@grafana01 ~]# <span style="color: #ff0000;"><strong>vi /etc/yum.repos.d/grafana.repo</strong></span>
<span style="color: #ff0000;"><em>[grafana]</em></span>
<span style="color: #ff0000;"><em>name=grafana</em></span>
<span style="color: #ff0000;"><em>baseurl=https://packages.grafana.com/oss/rpm</em></span>
<span style="color: #ff0000;"><em>repo_gpgcheck=1</em></span>
<span style="color: #ff0000;"><em>enabled=1</em></span>
<span style="color: #ff0000;"><em>gpgcheck=1</em></span>
<span style="color: #ff0000;"><em>gpgkey=https://packages.grafana.com/gpg.key</em></span>
<span style="color: #ff0000;"><em>sslverify=1</em></span>
<span style="color: #ff0000;"><em>sslcacert=/etc/pki/tls/certs/ca-bundle.crt</em></span></pre>
<pre>[root@grafana01 ~]#<span style="color: #ff0000;"><strong> yum update</strong></span>
[root@grafana01 ~]# <span style="color: #ff0000;"><strong>yum install grafana</strong></span></pre>
<p><strong>Installation de font du Supplémentaire </strong></p>
<pre>[root@grafana01 ~]# <span style="color: #ff0000;"><strong>yum install fontconfig freetype* urw-fonts</strong></span></pre>
<p><strong>Activer Grafana </strong></p>
<pre>[root@grafana01 ~]# <strong><span style="color: #ff0000;">systemctl start grafana-server &amp;&amp; systemctl enable grafana-server</span></strong>
[root@grafana01 ~]#<span style="color: #ff0000;"><strong> systemctl status grafana-server</strong></span></pre>
<p><img loading="lazy" decoding="async" width="1712" height="287" class="wp-image-3370" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-234.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-234.png 1712w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-234-300x50.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-234-1024x172.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-234-768x129.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-234-1536x257.png 1536w" sizes="auto, (max-width: 1712px) 100vw, 1712px" /></p>
<p><strong>Régle de Firewall</strong></p>
<pre>[root@grafana01 ~]# <span style="color: #ff0000;"><strong>firewall-cmd --zone=public --add-port=3000/tcp --permanent</strong></span>
[root@grafana01 ~]# <strong><span style="color: #ff0000;">firewall-cmd --reload</span></strong></pre>
<ul>
<li><a href="http://grafana01.house.cpb:3000/">http://grafana01.house.cpb:3000/</a></li>
</ul>
<p>Login/Password :<span style="color: #ff0000;"><strong> admin/admin</strong></span></p>
<p><img loading="lazy" decoding="async" width="1171" height="456" class="wp-image-3371" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-235.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-235.png 1171w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-235-300x117.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-235-1024x399.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-235-768x299.png 768w" sizes="auto, (max-width: 1171px) 100vw, 1171px" /></p>
<h4><span style="text-decoration: underline;"><span style="color: #000000; text-decoration: underline;"><strong>7°) Installation Promotheus</strong></span></span></h4>
<ul>
<li><a href="https://prometheus.io/download/">https://prometheus.io/download/</a></li>
</ul>
<p><img loading="lazy" decoding="async" width="1001" height="226" class="wp-image-3372" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-236.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-236.png 1001w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-236-300x68.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-236-768x173.png 768w" sizes="auto, (max-width: 1001px) 100vw, 1001px" /></p>
<pre>[root@grafana01 ~]#<strong><span style="color: #ff0000;"> cd /home/chris</span></strong>
[root@grafana01 chris]# <strong><span style="color: #ff0000;">wget <a style="color: #ff0000;" href="https://github.com/prometheus/prometheus/releases/download/v2.8.1/prometheus-2.8.1.linux-amd64.tar.gz">https://github.com/prometheus/prometheus/releases/download/v2.8.1/prometheus-2.8.1.linux-amd64.tar.gz</a></span></strong>
[root@grafana01 chris]# <strong><span style="color: #ff0000;">tar xzvf prometheus-2.8.1.linux-amd64.tar.gz</span></strong>
[root@grafana01 chris]# <span style="color: #ff0000;"><strong>mv prometheus-2.8.1.linux-amd64 prometheuspackage</strong></span></pre>
<p><strong>Création User Promotheus</strong></p>
<pre>[root@grafana01 chris]#<strong><span style="color: #ff0000;"> useradd --no-create-home --shell /bin/false prometheus</span></strong></pre>
<p><strong>Création structure Promotheus</strong></p>
<pre>[root@grafana01 chris]# <span style="color: #ff0000;"><strong>mkdir /etc/prometheus</strong></span>
[root@grafana01 chris]# <span style="color: #ff0000;"><strong>mkdir /var/lib/prometheus</strong></span>
[root@grafana01 chris]#<span style="color: #ff0000;"><strong> chown prometheus:prometheus /etc/prometheus</strong></span>
[root@grafana01 chris]# <span style="color: #ff0000;"><strong>chown prometheus:prometheus /var/lib/prometheus</strong></span></pre>
<p><strong>Copier les binaires sur la structure Promotheus</strong></p>
<pre>[root@grafana01 chris]# <span style="color: #ff0000;"><strong>cp prometheuspackage/prometheus /usr/local/bin/</strong></span>
[root@grafana01 chris]# <span style="color: #ff0000;"><strong>cp prometheuspackage/promtool /usr/local/bin/</strong></span>
[root@grafana01 chris]# <span style="color: #ff0000;"><strong>chown prometheus:prometheus /usr/local/bin/prometheus</strong></span>
[root@grafana01 chris]# <span style="color: #ff0000;"><strong>chown prometheus:prometheus /usr/local/bin/promtool</strong></span></pre>
<p><strong>Copier les fichiers conf sur la structure Promotheus</strong></p>
<pre>[root@grafana01 chris]# <span style="color: #ff0000;"><strong>cp -r prometheuspackage/consoles /etc/prometheus</strong></span>
[root@grafana01 chris]# <span style="color: #ff0000;"><strong>cp -r prometheuspackage/console_libraries /etc/prometheus</strong></span>
[root@grafana01 chris]# <span style="color: #ff0000;"><strong>chown -R prometheus:prometheus /etc/prometheus/consoles</strong></span>
[root@grafana01 chris]# <span style="color: #ff0000;"><strong>chown -R prometheus:prometheus /etc/prometheus/console_libraries</strong></span></pre>
<p><strong>Configurer Promotheus</strong></p>
<pre>[root@grafana01 chris]# <strong><span style="color: #ff0000;">vi /etc/prometheus/prometheus.yml</span></strong>
<span style="color: #ff0000;"><em>global:</em></span>
<span style="color: #ff0000;"><em>     scrape_interval: 10s</em></span>

<span style="color: #ff0000;"><em>scrape_configs:</em></span>
<span style="color: #ff0000;"><em>      - job_name: 'pve'</em></span>
<span style="color: #ff0000;"><em>        scrape_interval: 5s</em></span>
<span style="color: #ff0000;"><em>        metrics_path: /pve</em></span>
<span style="color: #ff0000;"><em>        static_configs:</em></span>
<span style="color: #ff0000;"><em>           - targets: ['</em><strong><em>IP_PROXMOX</em></strong><em>:9221']</em></span></pre>
<pre>[root@grafana01 chris]#<span style="color: #ff0000;"><strong> chown prometheus:prometheus /etc/prometheus/prometheus.yml</strong></span></pre>
<p><strong>Création du service Promotheus</strong></p>
<pre>[root@grafana01 chris]# <span style="color: #ff0000;"><strong>vi /etc/systemd/system/prometheus.service</strong></span>
<span style="color: #ff0000;"><em>[Unit]</em></span>
<span style="color: #ff0000;"><em>Description=Prometheus</em></span>
<span style="color: #ff0000;"><em>Wants=network-online.target</em></span>
<span style="color: #ff0000;"><em>After=network-online.target</em></span>

<span style="color: #ff0000;"><em>[Service]</em></span>
<span style="color: #ff0000;"><em>User=prometheus</em></span>
<span style="color: #ff0000;"><em>Group=prometheus</em></span>
<span style="color: #ff0000;"><em>Type=simple</em></span>
<span style="color: #ff0000;"><em>ExecStart=/usr/local/bin/prometheus \</em></span>
<span style="color: #ff0000;"><em>--config.file /etc/prometheus/prometheus.yml \</em></span>
<span style="color: #ff0000;"><em>--storage.tsdb.path /var/lib/prometheus/ \</em></span>
<span style="color: #ff0000;"><em>--web.console.templates=/etc/prometheus/consoles \</em></span>
<span style="color: #ff0000;"><em>--web.console.libraries=/etc/prometheus/console_libraries</em></span>

<span style="color: #ff0000;"><em>[Install]</em></span>
<span style="color: #ff0000;"><em>WantedBy=multi-user.target</em></span></pre>
<p><strong>Démarrage du service Promotheus</strong></p>
<pre>[root@grafana01 chris]#<span style="color: #ff0000;"><strong> systemctl daemon-reload</strong></span>
[root@grafana01 chris]# <span style="color: #ff0000;"><strong>systemctl start prometheus</strong></span>
[root@grafana01 chris]# <span style="color: #ff0000;"><strong>systemctl status prometheus</strong></span></pre>
<p><img loading="lazy" decoding="async" width="1736" height="321" class="wp-image-3373" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-237.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-237.png 1736w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-237-300x55.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-237-1024x189.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-237-768x142.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-237-1536x284.png 1536w" sizes="auto, (max-width: 1736px) 100vw, 1736px" /></p>
<p><strong>Régle de Firewall</strong></p>
<pre>[root@grafana01 ~]#<span style="color: #ff0000;"><strong> firewall-cmd --zone=public --add-port=9090/tcp --permanent</strong></span>
[root@grafana01 ~]# <span style="color: #ff0000;"><strong>firewall-cmd --zone=public --add-port=9221/tcp --permanent</strong></span>
[root@grafana01 ~]#<span style="color: #ff0000;"><strong> firewall-cmd --reload</strong></span></pre>
<ul>
<li><a href="http://grafana01.house.cpb:9090/">http://grafana01.house.cpb:9090/</a></li>
</ul>
<p><img loading="lazy" decoding="async" width="1151" height="441" class="wp-image-3374" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-238.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-238.png 1151w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-238-300x115.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-238-1024x392.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-238-768x294.png 768w" sizes="auto, (max-width: 1151px) 100vw, 1151px" /></p>
<h4><span style="text-decoration: underline;"><span style="color: #000000;"><strong>8°) Installation Proxmox-pve-exporter<span style="color: #ff0000; text-decoration: underline;"> (Serveur PROXMOX)</span></strong></span></span></h4>
<p><strong>Créer un user pve_exporter Spécifique à Proxmox</strong></p>
<pre>root@floki03:~# <strong><span style="color: #ff0000;">pveum groupadd monitoring -comment 'Monitoring group'</span></strong>
root@floki03:~# <strong><span style="color: #ff0000;">pveum aclmod / -group monitoring -role PVEAuditor</span></strong>
root@floki03:~# <span style="color: #ff0000;"><strong>pveum useradd pve_exporter@pve</strong></span>
root@floki03:~# <strong><span style="color: #ff0000;">pveum usermod pve_exporter@pve -group monitoring</span></strong>
root@floki03:~# <span style="color: #ff0000;"><strong>pveum passwd pve_exporter@pve</strong></span></pre>
<p><strong>Installation de l’exporter pve</strong></p>
<pre>root@floki03:~# <strong><span style="color: #ff0000;">apt-get install python-pip</span></strong>
root@floki03:~#<span style="color: #ff0000;"><strong> pip install prometheus-pve-exporter</strong></span></pre>
<p><img loading="lazy" decoding="async" width="1463" height="223" class="wp-image-3375" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-239.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-239.png 1463w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-239-300x46.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-239-1024x156.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-239-768x117.png 768w" sizes="auto, (max-width: 1463px) 100vw, 1463px" /></p>
<p><strong>Fichier de conf à pour la connexion à l’utilisateur privilégié </strong></p>
<pre>root@floki03:~# <strong><span style="color: #ff0000;">mkdir -p /usr/share/pve_exporter/</span></strong></pre>
<pre>root@floki03:~#<span style="color: #ff0000;"><strong> vi /usr/share/pve_exporter/pve_exporter.yml</strong></span>
<span style="color: #ff0000;"><em>default:</em></span>
<span style="color: #ff0000;"><em>         user: <strong>pve_exporter@pve</strong></em></span>
<span style="color: #ff0000;"><em>         password: "<strong>mot_de_passe user_exporter"</strong></em></span>
<span style="color: #ff0000;"><em>         verify_ssl: <strong>false</strong></em></span></pre>
<p><strong>Création du service pve exporter</strong></p>
<pre>root@floki03:~# <span style="color: #ff0000;"><strong>vi /etc/systemd/system/pve_exporter.service</strong></span>
<span style="color: #ff0000;"><em>[Unit]</em></span>
<span style="color: #ff0000;"><em>Description=Proxmox VE Prometheus Exporter</em></span>
<span style="color: #ff0000;"><em>After=network.target</em></span>
<span style="color: #ff0000;"><em>Wants=network.target</em></span>

<span style="color: #ff0000;"><em>[Service]</em></span>
<span style="color: #ff0000;"><em>Restart=on-failure</em></span>
<span style="color: #ff0000;"><em>WorkingDirectory=/usr/share/pve_exporter</em></span>
<span style="color: #ff0000;"><em>ExecStart=/usr/local/bin/pve_exporter /usr/share/pve_exporter/pve_exporter.yml 9221 </em><strong><em>IP_PROXMOX</em></strong></span>

<span style="color: #ff0000;"><em>[Install]</em></span>
<span style="color: #ff0000;"><em>WantedBy=multi-user.target</em></span></pre>
<p><strong>Lancer le service pve exporter</strong></p>
<pre>root@floki03:~# <span style="color: #ff0000;"><strong>systemctl daemon-reload</strong></span>
root@floki03:~# <span style="color: #ff0000;"><strong>systemctl enable pve_exporter</strong></span>
root@floki03:~# <span style="color: #ff0000;"><strong>systemctl start pve_exporter</strong></span></pre>
<p><img loading="lazy" decoding="async" width="1097" height="209" class="wp-image-3376" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-240.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-240.png 1097w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-240-300x57.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-240-1024x195.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-240-768x146.png 768w" sizes="auto, (max-width: 1097px) 100vw, 1097px" /></p>
<h4><span style="text-decoration: underline; color: #000000;"><strong>9°) ADD Promotheus source dans Grafana (grafana01)</strong></span></h4>
<p><strong>Connexion de Grafana et Promotheus</strong></p>
<p><img loading="lazy" decoding="async" width="923" height="223" class="wp-image-3377" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-241.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-241.png 923w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-241-300x72.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-241-768x186.png 768w" sizes="auto, (max-width: 923px) 100vw, 923px" /><br />
« Ajouter une source de données»</p>
<p><img loading="lazy" decoding="async" width="744" height="243" class="wp-image-3378" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-242.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-242.png 744w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-242-300x98.png 300w" sizes="auto, (max-width: 744px) 100vw, 744px" /></p>
<p>« Choisir la source de données &#8211; Prometheus»</p>
<p><img loading="lazy" decoding="async" width="1095" height="330" class="wp-image-3379" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-243.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-243.png 1095w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-243-300x90.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-243-1024x309.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-243-768x231.png 768w" sizes="auto, (max-width: 1095px) 100vw, 1095px" /><br />
« Configurer la connexion entre Promotheus et Grafana »</p>
<p><strong>Importer un DashBoard spécifique à Proxmox</strong></p>
<p><img loading="lazy" decoding="async" width="246" height="205" class="wp-image-3380" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-244.png" /><br />
« Create» et « Import »</p>
<p>Il existe un référentiel de Dashboard différent disponible sur le site de Grafana.</p>
<ul>
<li>Ici on prend le DashBoard 10347</li>
</ul>
<p><img loading="lazy" decoding="async" width="668" height="210" class="wp-image-3381" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-245.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-245.png 668w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-245-300x94.png 300w" sizes="auto, (max-width: 668px) 100vw, 668px" /><br />
« Load »</p>
<p><img loading="lazy" decoding="async" width="827" height="525" class="wp-image-3382" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-246.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-246.png 827w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-246-300x190.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-246-768x488.png 768w" sizes="auto, (max-width: 827px) 100vw, 827px" /><br />
<img loading="lazy" decoding="async" width="1867" height="935" class="wp-image-3383" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-247.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-247.png 1867w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-247-300x150.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-247-1024x513.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-247-768x385.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-247-1536x769.png 1536w" sizes="auto, (max-width: 1867px) 100vw, 1867px" /><br />
<img loading="lazy" decoding="async" width="1857" height="944" class="wp-image-3384" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-248.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-248.png 1857w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-248-300x153.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-248-1024x521.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-248-768x390.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-248-1536x781.png 1536w" sizes="auto, (max-width: 1857px) 100vw, 1857px" /></p>
<p>Views: 67</p><p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-grafana-promotheus-pour-proxmox/">MODOP – Installation Grafana/promotheus pour PROXMOX</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-installation-grafana-promotheus-pour-proxmox/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MODOP &#8211; PARTIE 2 – Installation de clients pour GrayLOG</title>
		<link>https://coffeebreak.en-images.info/modop-partie-2-installation-de-clients-pour-graylog/</link>
					<comments>https://coffeebreak.en-images.info/modop-partie-2-installation-de-clients-pour-graylog/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Fri, 02 Jul 2021 14:59:28 +0000</pubDate>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[GrayLOG]]></category>
		<category><![CDATA[OS Linux]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Système]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=2803</guid>

					<description><![CDATA[<p>Seconde Partie du MODOP sur l'application GrayLOG. Cette Partie 2 aborde la partie Clientes ( NAS , LINUX , Windows , ESXi , vCenter ,etc.)</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-partie-2-installation-de-clients-pour-graylog/">MODOP &#8211; PARTIE 2 – Installation de clients pour GrayLOG</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h4><strong>Les items abordés </strong></h4>
<ul>
<li>Client Centos7</li>
<li>Client Windows Server/Win10</li>
<li>Client NAS NetApp</li>
<li>Client vSphère ESX VMware</li>
<li>Client vCenter VMware</li>
<li>Complément Rsyslog</li>
<li>Service Apache et Rsyslog</li>
<li>Service Mariadb,MySQL et Rsyslog</li>
<li>Service Notification GrayLOG</li>
</ul>
<h4><strong>1°) Création d’un « Tube » Syslog UDP </strong></h4>
<p><img loading="lazy" decoding="async" width="777" height="465" class="wp-image-2807" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-27.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-27.png 777w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-27-300x180.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-27-768x460.png 768w" sizes="auto, (max-width: 777px) 100vw, 777px" /></p>
<p>Création d&rsquo;une entrée « INPUTS »</p>
<p><img loading="lazy" decoding="async" width="712" height="95" class="wp-image-2809" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-28.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-28.png 712w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-28-300x40.png 300w" sizes="auto, (max-width: 712px) 100vw, 712px" /></p>
<p>Définir « Syslog UDP »</p>
<p><img loading="lazy" decoding="async" width="547" height="770" class="wp-image-2812" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-29.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-29.png 547w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-29-213x300.png 213w" sizes="auto, (max-width: 547px) 100vw, 547px" /></p>
<p><img loading="lazy" decoding="async" width="925" height="291" class="wp-image-2814" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-30.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-30.png 925w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-30-300x94.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-30-768x242.png 768w" sizes="auto, (max-width: 925px) 100vw, 925px" /></p>
<h4><strong>2°) Client Linux Centos7 </strong></h4>
<pre>[root@centos ~]#<span style="color: #ff0000;"><strong> cd /etc/</strong></span>
[root@centos ~]#<strong><span style="color: #ff0000;"> ls -al |grep syslog</span></strong>
<em><span style="color: #ff0000;">-rw-r--r-- 1 root root 3256 16 mai 2018 rsyslog.conf</span></em>
<em><span style="color: #ff0000;">drwxr-xr-x. 2 root root 25 16 avril 2018 rsyslog.d</span></em></pre>
<pre>[root@centos ~]# <strong><span style="color: #ff0000;">vi rsyslog.conf</span></strong>
Ajouter à la fin du fichier
<em><span style="color: #ff0000;">*.* @192.168.1.148:5140 ;RSYSLOG_SyslogProtocol23Format</span></em></pre>
<pre>[root@centos ~]#<span style="color: #ff0000;"><strong> systemctl restart rsyslog</strong></span></pre>
<h4><span style="text-decoration: underline;">Coté Serveur</span></h4>
<pre>[root@superlog ~]# <span style="color: #ff0000;"><strong>yum install tcpdump</strong></span></pre>
<p><strong>On regarde si les trames udp passe entre les deux machines</strong></p>
<pre>[root@Superlog ~]# <strong><span style="color: #ff0000;">tcpdump -i ens192 -n | grep IP_Machine_Cliente</span></strong></pre>
<p>Les trames de communication entre superlog et la machine cliente (Centos7) vont apparaitre</p>
<p><img loading="lazy" decoding="async" width="1386" height="554" class="wp-image-2815" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-31.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-31.png 1386w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-31-300x120.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-31-1024x409.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-31-768x307.png 768w" sizes="auto, (max-width: 1386px) 100vw, 1386px" /></p>
<h4>3°) Client Windows Serveur / Windsows7 &#8211; 10</h4>
<p><b>Télécharger</b><strong> le freeware EvtSys (32bits ou 64bits)</strong></p>
<ul>
<li><strong><span style="color: #ff0000;"><a style="color: #ff0000;" href="https://code.google.com/archive/p/eventlog-to-syslog/downloads">https://code.google.com/archive/p/eventlog-to-syslog/downloads</a></span></strong></li>
</ul>
<p>Dézipper l’archive sur C:\<br />
Exécuter un terminal DOS en mode Administrateur</p>
<pre>C:\&gt;<strong><span style="color: #ff0000;">cd 64-Bit-LP</span></strong>
C:\64-Bit-LP&gt;<span style="color: #ff0000;"><strong>evtsys.exe -i -h superlog.house.cpb</strong></span></pre>
<p>Dans la base de Registre on devrait retrouver différentes clefs<br />
<img loading="lazy" decoding="async" width="914" height="306" class="wp-image-2817" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-32.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-32.png 914w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-32-300x100.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-32-768x257.png 768w" sizes="auto, (max-width: 914px) 100vw, 914px" /></p>
<p><strong>Modifier le port UDP 514 vers UDP5140</strong><br />
<img loading="lazy" decoding="async" width="574" height="281" class="wp-image-2820" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-33.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-33.png 574w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-33-300x147.png 300w" sizes="auto, (max-width: 574px) 100vw, 574px" /></p>
<p><strong>Il est possible de charger le Port UDP directement via la commande suivante</strong></p>
<pre>C:\64-Bit-LP&gt;<span style="color: #ff0000;"><strong>evtsys.exe -i -h Superlog.house.cpb -p 5140</strong></span></pre>
<p><strong>Lancement du Service </strong></p>
<pre>C:\64-Bit-LP&gt;<span style="color: #ff0000;"><strong>net start evtsys</strong></span>
<span style="color: #ff0000;"><em>Le service Eventlog to Syslog démarre.</em></span>
<span style="color: #ff0000;"><em>Le service Eventlog to Syslog a démarré.</em></span></pre>
<p><img loading="lazy" decoding="async" width="955" height="230" class="wp-image-2822" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-34.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-34.png 955w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-34-300x72.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-34-768x185.png 768w" sizes="auto, (max-width: 955px) 100vw, 955px" /></p>
<h4>4°) Client NAS NetApp (ex: nas1.house.cpb)</h4>
<p>Pour l’accès au fichier de configuration Syslog sur les NAS NetAPP,  il faut monter le système en partage CIFS.</p>
<p><img loading="lazy" decoding="async" width="1274" height="155" class="wp-image-2823" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-35.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-35.png 1274w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-35-300x36.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-35-1024x125.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-35-768x93.png 768w" sizes="auto, (max-width: 1274px) 100vw, 1274px" /></p>
<p>Monter le partage <a href="file:///\\nas1.house.cpb\c$">\\nas1.house.cpb\c$</a> sur l’explorateur de fichier windows.<br />
Copier le fichier « syslog.conf.sample » en « syslog.conf » situé sur /etc.</p>
<p><img loading="lazy" decoding="async" width="951" height="129" class="wp-image-2825" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-36.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-36.png 951w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-36-300x41.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-36-768x104.png 768w" sizes="auto, (max-width: 951px) 100vw, 951px" /></p>
<p>Editer le fichier syslog.conf et ajouter à la fin du fichier « <strong><span style="color: #ff0000;">*.* @Superlog </span></strong>»<br />
Editer le fichier hosts et ajouter à la fin du fichier « <span style="color: #ff0000;"><strong>192.168.1.48 Superlog</strong></span> »</p>
<p><strong>Vérifions la réception des trames sur le serveur Superlog.</strong></p>
<pre>[root@Superlog ~]# <span style="color: #ff0000;"><strong>tcpdump -vv -i ens192 -X port 514 -c 10</strong></span></pre>
<p><img loading="lazy" decoding="async" width="1575" height="452" class="wp-image-2828" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-37.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-37.png 1575w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-37-300x86.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-37-1024x294.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-37-768x220.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-37-1536x441.png 1536w" sizes="auto, (max-width: 1575px) 100vw, 1575px" /></p>
<p>Le Syslog NetApp envoi les trames uniquement sur le Port 514.</p>
<h4><span style="text-decoration: underline;">Sur le Serveur GrayLOG</span></h4>
<p><strong>Faire un transfert de port pour l’ajout des trames 514/udp vers 5410/upd</strong></p>
<pre>[root@Superlog ~]# <strong><span style="color: #ff0000;">firewall-cmd --zone=public --add-forward-port=port=514:proto=udp:toport=5140 --permanent</span></strong>
[root@Superlog ~]# <strong><span style="color: #ff0000;">firewall-cmd --reload</span></strong></pre>
<p><img loading="lazy" decoding="async" width="1138" height="311" class="wp-image-2830" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-38.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-38.png 1138w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-38-300x82.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-38-1024x280.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-38-768x210.png 768w" sizes="auto, (max-width: 1138px) 100vw, 1138px" /></p>
<h4>5°) Client Serveur ESXi VMWare (ex: esi01.house.cpb)</h4>
<p><strong>Se connecter à l’interface Web du Serveur ESXi</strong><br />
<img loading="lazy" decoding="async" width="1666" height="389" class="wp-image-2831" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-39.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-39.png 1666w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-39-300x70.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-39-1024x239.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-39-768x179.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-39-1536x359.png 1536w" sizes="auto, (max-width: 1666px) 100vw, 1666px" /></p>
<p><strong>Vérifier/Démarrer le service Syslog</strong><br />
<img loading="lazy" decoding="async" width="1382" height="366" class="wp-image-2833" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-40.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-40.png 1382w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-40-300x79.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-40-1024x271.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-40-768x203.png 768w" sizes="auto, (max-width: 1382px) 100vw, 1382px" /><br />
<img loading="lazy" decoding="async" width="1086" height="239" class="wp-image-2834" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-41.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-41.png 1086w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-41-300x66.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-41-1024x225.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-41-768x169.png 768w" sizes="auto, (max-width: 1086px) 100vw, 1086px" /></p>
<h4>6°) Client Serveur Vcenter VMWare (ex: vcenter01.house.cpb)</h4>
<p>Se connecter sur l’Appliance VMWare Vsphere</p>
<ol>
<li style="list-style-type: none;">
<ol>
<li style="list-style-type: none;">
<ul>
<li><a href="https://vcenter01.house.cpb:5480/login">https://vcenter01.house.cpb:5480/login</a></li>
</ul>
</li>
</ol>
</li>
</ol>
<p><img loading="lazy" decoding="async" width="1235" height="462" class="wp-image-2835" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-42.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-42.png 1235w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-42-300x112.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-42-1024x383.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-42-768x287.png 768w" sizes="auto, (max-width: 1235px) 100vw, 1235px" /><br />
<img loading="lazy" decoding="async" width="751" height="298" class="wp-image-2837" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-43.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-43.png 751w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-43-300x119.png 300w" sizes="auto, (max-width: 751px) 100vw, 751px" /><br />
<img loading="lazy" decoding="async" width="907" height="352" class="wp-image-2840" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-44.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-44.png 907w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-44-300x116.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-44-768x298.png 768w" sizes="auto, (max-width: 907px) 100vw, 907px" /></p>
<p>Ennoyer un test message en cliquant sur l’onglet « ENVOYER UN MESSAGE DE TEST »<br />
<img loading="lazy" decoding="async" width="673" height="385" class="wp-image-2842" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-45.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-45.png 673w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-45-300x172.png 300w" sizes="auto, (max-width: 673px) 100vw, 673px" /><br />
<img loading="lazy" decoding="async" width="1146" height="159" class="wp-image-2843" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-46.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-46.png 1146w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-46-300x42.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-46-1024x142.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-46-768x107.png 768w" sizes="auto, (max-width: 1146px) 100vw, 1146px" /></p>
<h4>7°) <strong>Complément pour les nouveaux paquets Rsyslog</strong></h4>
<pre>[root@cento7-1]#<strong><span style="color: #ff0000;"> cd /etc/yum.repos.d</span></strong>
[root@cento7-1]#<span style="color: #ff0000;"><strong> vi rsyslog.repo</strong></span>

<span style="color: #ff0000;"><em>[rsyslog_v8_nightly]</em></span>
<span style="color: #ff0000;"><em>name=Adiscon CentOS-$releasever - nightly packages for $basearch</em></span>
<span style="color: #ff0000;"><em>baseurl=http://rpms.adiscon.com/v8-stable-nightly/epel-$releasever/$basearch</em></span>
<span style="color: #ff0000;"><em>enabled=1</em></span>
<span style="color: #ff0000;"><em>gpgcheck=0</em></span>
<span style="color: #ff0000;"><em>gpgkey=http://rpms.adiscon.com/RPM-GPG-KEY-Adiscon</em></span>
<span style="color: #ff0000;"><em>protect=1</em></span></pre>
<pre>[root@cento7-1]# <span style="color: #ff0000;"><strong>yum install rsyslog</strong></span>
[root@cento7-1]# <span style="color: #ff0000;"><strong>systemctl enable rsyslog</strong></span></pre>
<pre>
[root@cento7-1]#<span style="color: #ff0000;"><strong> vi /etc/rsyslog.conf</strong></span>
<span style="color: #ff0000;"><em>*.* 192.168.1.148:5140;RSYSLOG_SyslogProtocol23Format</em></span></pre>
<pre>[root@cento7-1]# <span style="color: #ff0000;"><strong>systemctl start rsyslog</strong></span></pre>
<h4>8°) <strong>Intégrer les Logs Apache dans Rsyslog/Graylog </strong></h4>
<p><strong>Editer le fichier de conf SITE sur /etc/httpd/conf.d</strong><br />
Ajouter les lignes suivantes</p>
<pre><span style="color: #ff0000;">## Passage des log vers Rsyslog</span>
<span style="color: #ff0000;">ErrorLog "|/usr/bin/logger -t apache -p local6.info"</span>
<span style="color: #ff0000;">CustomLog "|/usr/bin/logger -t apache -p local6.info" combined</span></pre>
<p><img loading="lazy" decoding="async" width="613" height="151" class="wp-image-2845" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-47.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-47.png 613w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-47-300x74.png 300w" sizes="auto, (max-width: 613px) 100vw, 613px" /></p>
<p><strong>Sauvegarder et redémarrer le service apache et le service syslog</strong></p>
<pre>[root@cento7-1]#<strong><span style="color: #ff0000;"> service httpd restart</span></strong>
[root@cento7-1]#<strong><span style="color: #ff0000;"> service rsyslog restart</span></strong></pre>
<h4>9°) <strong>Intégrer les Logs Mariadb,Mysql dans Rsyslog/Graylog </strong></h4>
<p><strong>Editer le fichier /etc/my.cnf et ajouter les lignes suivantes.</strong></p>
<pre><span style="color: #ff0000;"><em>###### Collect des logs via Rsyslog</em></span>
<span style="color: #ff0000;"><em>log_error=/var/log/mariadb/mysql_error.log</em></span>
<span style="color: #ff0000;"><em>general_log_file = /var/log/mariadb/mysql.log</em></span>
<span style="color: #ff0000;"><em>general_log = 1</em></span></pre>
<p><strong>Redémarrer le service mariadb</strong></p>
<pre>[root@cento7-1]# <strong><span style="color: #ff0000;">service mariadb restart</span></strong>
[root@cento7-1]# <strong><span style="color: #ff0000;">tail -f mariadb/mariadb.log</span></strong></pre>
<p><img loading="lazy" decoding="async" width="1700" height="580" class="wp-image-2848" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-48.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-48.png 1700w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-48-300x102.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-48-1024x349.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-48-768x262.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-48-1536x524.png 1536w" sizes="auto, (max-width: 1700px) 100vw, 1700px" /></p>
<p><strong>Editer le fichier de conf Rsyslog /etc/rsyslog.conf et ajouter les lignes suivantes.</strong></p>
<pre><span style="color: #ff0000;"><em>module(load="imfile" PollingInterval="1")</em></span>
<span style="color: #ff0000;"><em>input(type="imfile"</em></span>
<span style="color: #ff0000;"><em> File="/var/log/mariadb/mysql.log"</em></span>
<span style="color: #ff0000;"><em> stateFile="statefile-mysql-general"</em></span>
<span style="color: #ff0000;"><em> Tag="mysql-general"</em></span>
<span style="color: #ff0000;"><em> Severity="warning"</em></span>
<span style="color: #ff0000;"><em> Facility="local1")</em></span></pre>
<p><strong>Redémarrer le service Rsyslog</strong></p>
<pre>[root@cento7-1]#<strong><span style="color: #ff0000;"> service rsyslog restart</span></strong></pre>
<h3><span style="text-decoration: underline;">Côté Graylog</span></h3>
<p><img loading="lazy" decoding="async" width="1364" height="448" class="wp-image-2850" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-49.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-49.png 1364w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-49-300x99.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-49-1024x336.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-49-768x252.png 768w" sizes="auto, (max-width: 1364px) 100vw, 1364px" /></p>
<p><strong>Ajouter la rotation des logs</strong></p>
<pre>[root@cento7-1]# <strong><span style="color: #ff0000;">yum install gzip</span></strong></pre>
<p>Editer le fichier <strong>/etc/logrotate.conf</strong> et ajouter les lignes suivantes</p>
<pre><span style="color: #ff0000;"><em>/var/log/mariadb/*.log {</em></span>
<span style="color: #ff0000;"><em>      daily</em></span>
<span style="color: #ff0000;"><em>      rotate 8</em></span>
<span style="color: #ff0000;"><em>      compress</em></span>
<span style="color: #ff0000;"><em>      delaycompress</em></span>
<span style="color: #ff0000;"><em>      missingok</em></span>
<span style="color: #ff0000;"><em>      notifempty</em></span>
<span style="color: #ff0000;"><em>      size 1M</em></span>
<span style="color: #ff0000;"><em>      create 440 root root</em></span>
<span style="color: #ff0000;"><em>}</em></span></pre>
<p>Lancer la rotation des logs en ligne de commande pour test</p>
<pre>[root@cento7-1]# <span style="color: #ff0000;"><strong>logrotate -f /etc/logrotate.conf</strong></span></pre>
<h4>10°) Ajout de règle d’alerte par notification de mail</h4>
<p><strong>Exemple une alerte concernant l’arrêt d’un service (ex vmtools)</strong><br />
<img loading="lazy" decoding="async" width="1412" height="376" class="wp-image-2851" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-50.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-50.png 1412w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-50-300x80.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-50-1024x273.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-50-768x205.png 768w" sizes="auto, (max-width: 1412px) 100vw, 1412px" /></p>
<p>Création d’un Stream pour encapsuler nos critères<br />
<img loading="lazy" decoding="async" width="1896" height="162" class="wp-image-2853" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-51.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-51.png 1896w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-51-300x26.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-51-1024x87.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-51-768x66.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-51-1536x131.png 1536w" sizes="auto, (max-width: 1896px) 100vw, 1896px" /><br />
<img loading="lazy" decoding="async" width="621" height="474" class="wp-image-2856" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-52.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-52.png 621w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-52-300x229.png 300w" sizes="auto, (max-width: 621px) 100vw, 621px" /><br />
<img loading="lazy" decoding="async" width="1382" height="86" class="wp-image-2858" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-53.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-53.png 1382w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-53-300x19.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-53-1024x64.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-53-768x48.png 768w" sizes="auto, (max-width: 1382px) 100vw, 1382px" /><br />
<img loading="lazy" decoding="async" width="1382" height="211" class="wp-image-2859" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-54.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-54.png 1382w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-54-300x46.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-54-1024x156.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-54-768x117.png 768w" sizes="auto, (max-width: 1382px) 100vw, 1382px" /><br />
<img loading="lazy" decoding="async" width="599" height="482" class="wp-image-2861" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-55.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-55.png 599w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-55-300x241.png 300w" sizes="auto, (max-width: 599px) 100vw, 599px" /><br />
<img loading="lazy" decoding="async" width="368" height="162" class="wp-image-2864" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-56.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-56.png 368w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-56-300x132.png 300w" sizes="auto, (max-width: 368px) 100vw, 368px" /><br />
<img loading="lazy" decoding="async" width="594" height="491" class="wp-image-2866" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-57.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-57.png 594w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-57-300x248.png 300w" sizes="auto, (max-width: 594px) 100vw, 594px" /><br />
<img loading="lazy" decoding="async" width="466" height="132" class="wp-image-2867" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-58.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-58.png 466w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-58-300x85.png 300w" sizes="auto, (max-width: 466px) 100vw, 466px" /><br />
<img loading="lazy" decoding="async" width="710" height="97" class="wp-image-2869" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-59.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-59.png 710w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-59-300x41.png 300w" sizes="auto, (max-width: 710px) 100vw, 710px" /></p>
<h4><strong>Création d’une condition sur le stream</strong><br />
<img loading="lazy" decoding="async" width="1382" height="110" class="wp-image-2872" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-60.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-60.png 1382w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-60-300x24.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-60-1024x82.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-60-768x61.png 768w" sizes="auto, (max-width: 1382px) 100vw, 1382px" /><br />
<img loading="lazy" decoding="async" width="980" height="307" class="wp-image-2874" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-61.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-61.png 980w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-61-300x94.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-61-768x241.png 768w" sizes="auto, (max-width: 980px) 100vw, 980px" /><br />
<img loading="lazy" decoding="async" width="584" height="929" class="wp-image-2875" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-62.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-62.png 584w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-62-189x300.png 189w" sizes="auto, (max-width: 584px) 100vw, 584px" /></h4>
<h4><strong>Création d’une notification mail via la condition sur le stream « Service Stoppé »</strong><br />
<img loading="lazy" decoding="async" width="1384" height="104" class="wp-image-2877" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-63.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-63.png 1384w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-63-300x23.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-63-1024x77.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-63-768x58.png 768w" sizes="auto, (max-width: 1384px) 100vw, 1384px" /><br />
<img loading="lazy" decoding="async" width="986" height="308" class="wp-image-2880" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-64.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-64.png 986w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-64-300x94.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-64-768x240.png 768w" sizes="auto, (max-width: 986px) 100vw, 986px" /><br />
<img loading="lazy" decoding="async" width="580" height="851" class="wp-image-2882" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-65.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-65.png 580w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-65-204x300.png 204w" sizes="auto, (max-width: 580px) 100vw, 580px" /></h4>
<h4>11°) <strong>Information &#8211; Code Syslog </strong></h4>
<table>
<tbody>
<tr>
<td colspan="4"><strong>Codes de gravité</strong></td>
</tr>
<tr>
<td><strong>Code</strong></td>
<td><strong>Gravité</strong></td>
<td><strong>Mot-clé</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td><strong>0</strong></td>
<td>Emergency</td>
<td>emerg (panic)</td>
<td>Système inutilisable.</td>
</tr>
<tr>
<td><strong>1</strong></td>
<td>Alert</td>
<td>alert</td>
<td>Une intervention immédiate est nécessaire.</td>
</tr>
<tr>
<td><strong>2</strong></td>
<td>Critical</td>
<td>crit</td>
<td>Erreur critique pour le système.</td>
</tr>
<tr>
<td><strong>3</strong></td>
<td>Error</td>
<td>err (error)</td>
<td>Erreur de fonctionnement.</td>
</tr>
<tr>
<td><strong>4</strong></td>
<td>Warning</td>
<td>warn (warning)</td>
<td>Avertissement (une erreur peut intervenir si aucune action n&rsquo;est prise).</td>
</tr>
<tr>
<td><strong>5</strong></td>
<td>Notice</td>
<td>notice</td>
<td>Événement normal méritant d&rsquo;être signalé.</td>
</tr>
<tr>
<td><strong>6</strong></td>
<td>Informational</td>
<td>info</td>
<td>Pour information.</td>
</tr>
<tr>
<td><strong>7</strong></td>
<td>Debugging</td>
<td>debug</td>
<td>Message de mise au point.</td>
</tr>
</tbody>
</table>
<p>Views: 34</p><p>L’article <a href="https://coffeebreak.en-images.info/modop-partie-2-installation-de-clients-pour-graylog/">MODOP &#8211; PARTIE 2 – Installation de clients pour GrayLOG</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-partie-2-installation-de-clients-pour-graylog/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MODOP &#8211; PARTIE 1 – Installation GrayLog – Centraliser et Superviser les LOGS</title>
		<link>https://coffeebreak.en-images.info/modop-partie-1-installation-graylog-centraliser-et-superviser-les-logs/</link>
					<comments>https://coffeebreak.en-images.info/modop-partie-1-installation-graylog-centraliser-et-superviser-les-logs/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Fri, 02 Jul 2021 14:06:36 +0000</pubDate>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[GrayLOG]]></category>
		<category><![CDATA[RedHat/Centos Linux]]></category>
		<category><![CDATA[Système]]></category>
		<category><![CDATA[Centos]]></category>
		<category><![CDATA[GrayLog]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Serveur]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=2757</guid>

					<description><![CDATA[<p>GrayLog permet la centralisation et la supervision des logs Machines ou applicatifs. Compatible Multi OS.<br />
Ce MODOP est l'installation de la partie Serveur.</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-partie-1-installation-graylog-centraliser-et-superviser-les-logs/">MODOP &#8211; PARTIE 1 – Installation GrayLog – Centraliser et Superviser les LOGS</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" width="1164" height="667" class="wp-image-2759" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-13.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-13.png 1164w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-13-300x172.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-13-1024x587.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-13-768x440.png 768w" sizes="auto, (max-width: 1164px) 100vw, 1164px" /></p>
<h4>1°) Désactiver SELinux</h4>
<p><strong>Editer le fichier /etc/selinux/config</strong></p>
<pre>[root@Superlog ~]#<strong><span style="color: #ff0000;"> vi /etc/selinux/config</span></strong>

<em><span style="color: #ff0000;">SELINUX=<strong>disabled</strong></span></em></pre>
<h4>2°) <strong>Désactiver l’IPV6 (3 nœuds gfsw)</strong></h4>
<pre>[root@superlog ~]#<strong><span style="color: #ff0000;"> vi /etc/sysctl.conf</span></strong>
<span style="color: #ff0000;"><em>net.ipv6.conf.all.disable_ipv6 = 1</em></span>
<span style="color: #ff0000;"><em>net.ipv6.conf.all.autoconf = 0</em></span>
<span style="color: #ff0000;"><em>net.ipv6.conf.default.disable_ipv6 = 1</em></span>
<span style="color: #ff0000;"><em>net.ipv6.conf.default.autoconf = 0</em></span></pre>
<pre>[root@superlog ~]#<strong><span style="color: #ff0000;"> sysctl  -p</span></strong></pre>
<h4>3°) <strong>Instalation des packets utiles</strong></h4>
<pre>[root@superlog ~]# <span style="color: #ff0000;"><strong>yum -y update &amp;&amp; yum -y upgrade</strong></span>
[root@superlog ~]# <span style="color: #ff0000;"><strong>yum -y install epel-release</strong></span>
[root@superlog ~]# <span style="color: #ff0000;"><strong>yum -y install wget locate vim nmap pwgen</strong></span></pre>
<h4>4°) Installation JAVA8</h4>
<pre>[root@superlog ~]# <strong><span style="color: #ff0000;">yum -y install java-1.8.0-openjdk-headless.x86_64</span></strong>
[root@superlog ~]#<span style="color: #ff0000;"><strong> java -version</strong></span></pre>
<p><img loading="lazy" decoding="async" width="614" height="90" class="wp-image-2761" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-14.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-14.png 614w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-14-300x44.png 300w" sizes="auto, (max-width: 614px) 100vw, 614px" /></p>
<h4>5°) Installation ElasticSearch</h4>
<p>Création d’un dépôt ElasticSearch pour l’installation</p>
<p><strong>Importation des certificats GPG signing key ElasticSearch</strong></p>
<pre>[root@superlog ~]# <strong><span style="color: #ff0000;">rpm --import <a style="color: #ff0000;" href="https://artifacts.elastic.co/GPG-KEY-elasticsearch">https://artifacts.elastic.co/GPG-KEY-elasticsearch</a></span></strong></pre>
<pre>[root@superlog ~]# <span style="color: #ff0000;"><strong>vim /etc/yum.repos.d/elasticsearch.repo</strong></span>
<span style="color: #ff0000;"><em> [elasticsearch-6.x]</em></span>
<span style="color: #ff0000;"><em>name=Elasticsearch repository for 6.x packages</em></span>
<span style="color: #ff0000;"><em>baseurl=https://artifacts.elastic.co/packages/6.x/yum</em></span>
<span style="color: #ff0000;"><em>gpgcheck=1</em></span>
<span style="color: #ff0000;"><em>gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch</em></span>
<span style="color: #ff0000;"><em>enabled=1</em></span>
<span style="color: #ff0000;"><em>autorefresh=1</em></span>
<span style="color: #ff0000;"><em>type=rpm-md</em></span></pre>
<p><strong>Installation via le dépôt </strong></p>
<pre>[root@superlog ~]# <span style="color: #ff0000;"><strong>yum -y update &amp;&amp; yum install -y elasticsearch</strong></span></pre>
<p><strong>Configuration de ElastiSearch pour notre Cluster </strong></p>
<pre>[root@superlog ~]# <span style="color: #ff0000;"><strong>vim /etc/elasticsearch/elasticsearch.yml</strong></span></pre>
<p>Remplacer <em><span style="color: #ff0000;">#cluster.name: my-application</span></em><br />
Par<br />
<span style="color: #ff0000;"><strong>cluster.name: superlog</strong></span></p>
<p><img loading="lazy" decoding="async" width="676" height="138" class="wp-image-2764" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-15.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-15.png 676w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-15-300x61.png 300w" sizes="auto, (max-width: 676px) 100vw, 676px" /></p>
<p><strong>Activer au démarrage le service ElasticSearch</strong></p>
<pre>[root@superlog ~]# <strong><span style="color: #ff0000;">systemctl enable elasticsearch</span></strong>
[root@superlog ~]# <strong><span style="color: #ff0000;">systemctl start elasticsearch</span></strong>
[root@superlog ~]# <strong><span style="color: #ff0000;">systemctl status elasticsearch</span></strong></pre>
<p><img loading="lazy" decoding="async" width="1552" height="191" class="wp-image-2766" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-16.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-16.png 1552w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-16-300x37.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-16-1024x126.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-16-768x95.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-16-1536x189.png 1536w" sizes="auto, (max-width: 1552px) 100vw, 1552px" /></p>
<p><strong>Ajout des Rules Firewall Port 9200</strong></p>
<pre>[root@superlog ~]# <strong><span style="color: #ff0000;">firewall-cmd --zone=public --add-port=9200/tcp --permanent</span></strong>
[root@superlog ~]# <strong><span style="color: #ff0000;">firewall-cmd --reload</span></strong></pre>
<p><strong>Vérifions que le service travail bien sur le port 9200 du Cluster graylog</strong></p>
<pre>[root@superlog ~]# <strong><span style="color: #ff0000;">curl -XGET 'localhost:9200/?pretty'</span></strong></pre>
<p><img loading="lazy" decoding="async" width="651" height="301" class="wp-image-2767" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-17.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-17.png 651w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-17-300x139.png 300w" sizes="auto, (max-width: 651px) 100vw, 651px" /></p>
<p><strong>Vérifions l’état de santé du Cluster graylog</strong></p>
<pre>[root@superlog ~]#<span style="color: #ff0000;"><strong> curl -XGET 'http://localhost:9200/_cluster/health?pretty=true'</strong></span></pre>
<p><img loading="lazy" decoding="async" width="798" height="280" class="wp-image-2769" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-18.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-18.png 798w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-18-300x105.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-18-768x269.png 768w" sizes="auto, (max-width: 798px) 100vw, 798px" /></p>
<h4>6°) Installation MangoDB (BDD)</h4>
<p><strong>Création d’un dépôt pour l’installation de la base de données</strong></p>
<pre>[root@superlog ~]# <span style="color: #ff0000;"><strong>vim /etc/yum.repos.d/mongodb-org-4.0.repo</strong></span>

<em><span style="color: #ff0000;">[mongodb-org-4.0]</span></em>
<em><span style="color: #ff0000;">name=MongoDB Repository</span></em>
<em><span style="color: #ff0000;">baseurl=https://repo.mongodb.org/yum/redhat/$releasever/mongodb-org/4.0/x86_64/</span></em>
<em><span style="color: #ff0000;">gpgcheck=1</span></em>
<em><span style="color: #ff0000;">enabled=1</span></em>
<em><span style="color: #ff0000;">gpgkey=https://www.mongodb.org/static/pgp/server-4.0.asc</span></em></pre>
<p><strong>Installation du packet</strong></p>
<pre>[root@superlog ~]# <span style="color: #ff0000;"><strong>yum -y update &amp;&amp; yum install -y mongodb-org</strong></span>
[root@superlog ~]#<span style="color: #ff0000;"><strong> systemctl enable mongod</strong></span>
[root@superlog ~]# <strong><span style="color: #ff0000;">systemctl start mongod</span></strong>
[root@superlog ~]#<span style="color: #ff0000;"><strong> systemctl status mongod</strong></span></pre>
<p><img loading="lazy" decoding="async" width="993" height="310" class="wp-image-2772" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-19.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-19.png 993w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-19-300x94.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-19-768x240.png 768w" sizes="auto, (max-width: 993px) 100vw, 993px" /></p>
<p><strong>Ajout des Rules Firewall Port 3306</strong></p>
<pre>[root@superlog ~]#<span style="color: #ff0000;"><strong> firewall-cmd --zone=public --add-port=3306/tcp --permanent</strong></span>
[root@superlog ~]# <strong><span style="color: #ff0000;">firewall-cmd --reload</span></strong></pre>
<h4>7°) Installation GrayLog</h4>
<p><strong>Récupère le RPM de GrayLog</strong></p>
<pre>[root@superlog ~]# <strong><span style="color: #ff0000;">cd /home/chris</span></strong>
[root@superlog ~]# <strong><span style="color: #ff0000;">rpm -Uvh https://packages.graylog2.org/repo/packages/graylog-3.0-repository_latest.rpm</span></strong>

[root@superlog ~]# <strong><span style="color: #ff0000;">yum -y update</span></strong>
[root@superlog ~]# <span style="color: #ff0000;"><strong>yum -y install graylog-server</strong></span></pre>
<h4>8°) Configurer GrayLog</h4>
<p><strong>On va générer un mot de passe via pwgen</strong></p>
<pre>[root@superlog ~]#<strong><span style="color: #ff0000;"> pwgen -N 1 -s 96</span></strong>
<span style="color: #ff0000;"><em>AYyqGY7gZPpC0vyhXcF9IL1AvZhLKXJfAXm4P5Ip9xbxMSwPUt1cPc5ySHtIeN0QMyZH0QoqcAdGdxqCOm9nPwSBUoYC0pDA</em></span></pre>
<p><strong>On va générer un mot de passe pour le compte admin</strong></p>
<pre>[root@superlog ~]# <span style="color: #ff0000;">echo -n <strong>superlog@graylog</strong> | sha256sum</span>
<span style="color: #ff0000;"><em>8a84e1cfa88315c07c5a22b5aaaac7553c282b82d118cc86c1776e2a0c6aa3d6 -</em></span></pre>
<p><strong>Editer le fichier de conf de GrayLog</strong></p>
<pre>[root@superlog ~]#<span style="color: #ff0000;"><strong> vi /etc/graylog/server/server.conf</strong></span>

#Ajouter ces deux mots de passe fort
<span style="color: #ff0000;">password_secret = <strong><em>AYyqGY7gZPpC0vyhXcF9IL1AvZhLKXJfAXm4P5Ip9xbxMSwPUt1cPc5ySHtIeN0QMyZH0QoqcAdGdxqCOm9nPwSBUoYC0pDA</em></strong></span>
<span style="color: #ff0000;">root_password_sha2 = <strong><em>8a84e1cfa88315c07c5a22b5aaaac7553c282b82d118cc86c1776e2a0c6aa3d6</em></strong></span>
<span style="color: #ff0000;">root_email =<strong> "chris@en-images.info "</strong></span>
<span style="color: #ff0000;">root_timezone = <strong>Europe/Paris</strong></span>
<span style="color: #ff0000;">elasticsearch_max_docs_per_index =<strong> 20000000</strong></span>
<span style="color: #ff0000;">elasticsearch_max_number_of_indices = <strong>20</strong></span>
<span style="color: #ff0000;">elasticsearch_shards = <strong>1</strong></span>
<span style="color: #ff0000;">elasticsearch_replicas =<strong> 0</strong></span>
<span style="color: #ff0000;">http_bind_address = <strong>192.168.1.149:9000</strong></span></pre>
<p><strong>Démarrer au démarrage le server GrayLog</strong></p>
<pre>[root@superlog ~]# <span style="color: #ff0000;"><strong>systemctl enable graylog-server</strong></span>
[root@superlog ~]#<span style="color: #ff0000;"><strong> systemctl daemon-reload</strong></span>
[root@superlog ~]#<span style="color: #ff0000;"><strong> systemctl start graylog-server</strong></span>
[root@superlog ~]# <span style="color: #ff0000;"><strong>systemctl status graylog-server</strong></span></pre>
<p><img loading="lazy" decoding="async" width="1686" height="206" class="wp-image-2775" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-21.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-21.png 1686w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-21-300x37.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-21-1024x125.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-21-768x94.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-21-1536x188.png 1536w" sizes="auto, (max-width: 1686px) 100vw, 1686px" /></p>
<h4>9°) Installer les règles dans Iptables</h4>
<pre>[root@superlog ~]# <span style="color: #ff0000;"><strong>firewall-cmd --zone=public --permanent --add-service=http</strong></span>
[root@superlog ~]#<span style="color: #ff0000;"><strong> firewall-cmd --zone=public --permanent --add-port=9000/tcp</strong></span>
[root@superlog ~]# <span style="color: #ff0000;"><strong>firewall-cmd --zone=public --permanent --add-port=5140/udp</strong></span>
[root@superlog ~]#<span style="color: #ff0000;"><strong> firewall-cmd --reload</strong></span></pre>
<pre>[root@superlog ~]# <span style="color: #ff0000;"><strong>tailf /var/log/graylog-server/server.log</strong></span></pre>
<p><img loading="lazy" decoding="async" width="1572" height="345" class="wp-image-2777" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-22.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-22.png 1572w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-22-300x66.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-22-1024x225.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-22-768x169.png 768w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-22-1536x337.png 1536w" sizes="auto, (max-width: 1572px) 100vw, 1572px" /></p>
<h4>10°) Installons Nginx reverse Proxy</h4>
<pre>[root@superlog ~]# <span style="color: #ff0000;"><strong>yum -y install nginx</strong></span></pre>
<pre>[root@superlog ~]#<span style="color: #ff0000;"><strong> vi /etc/nginx/conf.d/graylog.conf</strong></span>
<span style="color: #ff0000;"><em>server</em></span>
<span style="color: #ff0000;"><em>{</em></span>
<span style="color: #ff0000;"><em>     listen 80 default_server;</em></span>
<span style="color: #ff0000;"><em>     server_name superlog.house.cpb;</em></span>
<span style="color: #ff0000;"><em>     location / {</em></span>
<span style="color: #ff0000;"><em>           proxy_set_header Host $http_host;</em></span>
<span style="color: #ff0000;"><em>           proxy_set_header X-Forwarded-Host $host;</em></span>
<span style="color: #ff0000;"><em>          proxy_set_header X-Forwarded-Server $host;</em></span>
<span style="color: #ff0000;"><em>          proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;</em></span>
<span style="color: #ff0000;"><em>         #proxy_pass http://127.0.0.1:9000;</em></span>
<span style="color: #ff0000;"><em>         proxy_pass http://superlog.house.cpb:9000;</em></span>
<span style="color: #ff0000;"><em>                }</em></span>
<span style="color: #ff0000;"><em>} </em></span></pre>
<p><strong>Edite le fichier nginx.conf et désactiver la conf par défaut</strong></p>
<pre>[root@superlog ~]#<span style="color: #ff0000;"><strong> vi /etc/nginx/nginx.conf</strong></span>
<span style="color: #ff0000;">
#</span> server {
<span style="color: #ff0000;">#</span> listen 80 default_server;
<span style="color: #ff0000;">#</span> listen [::]:80 default_server;
<span style="color: #ff0000;">#</span> server_name _;
<span style="color: #ff0000;">#</span> root /usr/share/nginx/html;
<span style="color: #ff0000;">#</span> Load configuration files for the default server block.
<span style="color: #ff0000;">#</span> include /etc/nginx/default.d/*.conf;
<span style="color: #ff0000;">#</span>
<span style="color: #ff0000;">#</span> location / {
<span style="color: #ff0000;">#</span> }
<span style="color: #ff0000;">#</span> error_page 404 /404.html;
<span style="color: #ff0000;">#</span> location = /40x.html {
<span style="color: #ff0000;">#</span> }
<span style="color: #ff0000;">#</span> error_page 500 502 503 504 /50x.html;
<span style="color: #ff0000;">#</span> location = /50x.html {
<span style="color: #ff0000;">#</span> }
<span style="color: #ff0000;">#</span> }</pre>
<pre>[root@superlog ~]# <span style="color: #ff0000;"><strong>systemctl enable nginx</strong></span>
[root@superlog ~]# <strong><span style="color: #ff0000;">systemctl start nginx</span></strong>
[root@superlog ~]# <strong><span style="color: #ff0000;">systemctl status nginx</span></strong></pre>
<p><img loading="lazy" decoding="async" width="1216" height="331" class="wp-image-2780" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-23.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-23.png 1216w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-23-300x82.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-23-1024x279.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-23-768x209.png 768w" sizes="auto, (max-width: 1216px) 100vw, 1216px" /></p>
<pre>[root@superlog ~]# <strong><span style="color: #ff0000;">echo "192.168.1.149 superlog.house.cpb" &gt;&gt; /etc/hosts</span></strong></pre>
<p>Si vous n’avez pas de DNS</p>
<ul>
<li>C:\Windows\System32\drivers\etc\hosts (mode Administrateur)</li>
</ul>
<p><span style="color: #ff0000;"><em>192.168.1.149 superlog.house.cpb</em></span></p>
<p>Connexion à l’interface Web via Firefox ou Chrome</p>
<ul>
<li><a href="http://superlog.house.cpb/">http://superlog.house.cpb/</a></li>
</ul>
<p><img loading="lazy" decoding="async" width="1202" height="411" class="wp-image-2782" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-24.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-24.png 1202w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-24-300x103.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-24-1024x350.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-24-768x263.png 768w" sizes="auto, (max-width: 1202px) 100vw, 1202px" /><br />
<img loading="lazy" decoding="async" width="1362" height="471" class="wp-image-2783" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-25.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-25.png 1362w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-25-300x104.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-25-1024x354.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-25-768x266.png 768w" sizes="auto, (max-width: 1362px) 100vw, 1362px" /></p>
<h4>11°) <strong>Installation Client de synchronisation de temps </strong></h4>
<pre>[root@superlog ~]#<strong><span style="color: #ff0000;"> timedatectl status</span></strong></pre>
<p><img loading="lazy" decoding="async" width="903" height="262" class="wp-image-2785" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-26.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-26.png 903w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-26-300x87.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/07/word-image-26-768x223.png 768w" sizes="auto, (max-width: 903px) 100vw, 903px" /></p>
<p><strong>Installation du packet ntp Client via les sources apt</strong></p>
<pre>[root@superlog ~]# <span style="color: #ff0000;"><strong>yum -y install ntp</strong></span>
root@Superlog run]# <strong><span style="color: #ff0000;">systemctl enable ntpd</span></strong>
[root@Superlog run]# <strong><span style="color: #ff0000;">systemctl start ntpd</span></strong></pre>
<p><strong>Ajouter les Rules Firewall Port 123 NTP</strong></p>
<pre>[root@Superlog run]# <span style="color: #ff0000;"><strong>firewall-cmd --zone=public --permanent --add-service=ntp</strong></span>
[root@Superlog run]# <span style="color: #ff0000;"><strong>firewall-cmd --reload</strong></span></pre>
<p>Views: 101</p><p>L’article <a href="https://coffeebreak.en-images.info/modop-partie-1-installation-graylog-centraliser-et-superviser-les-logs/">MODOP &#8211; PARTIE 1 – Installation GrayLog – Centraliser et Superviser les LOGS</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-partie-1-installation-graylog-centraliser-et-superviser-les-logs/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
