Blog

Getting Data Into Gravwell

Jul 14, 2020 9:05:00 AM / by Ron Fabela

In our continuing series of HOWTOs, today we are getting some data into our Gravwell instance setup in Getting Gravwell Installed in 2 Minutes

As with install, setting up your data ingesters is quick and easy. 


Part 2:  Data Ingest Setup

(Collect all the things)

We'll be downloading and configuring our first data ingest today!  A current list can always be found here: https://dev.gravwell.io/docs/#!quickstart/downloads.md

Today we'll be looking at Netflow and PCAP.  These processes are thoroughly documented at https://dev.gravwell.io/docs/#!ingesters/ingesters.md#Netflow_Ingester and https://dev.gravwell.io/docs/#!ingesters/ingesters.md#Network_Ingester

Netflow Ingester Install

The process is simple and breaks down into the following steps:

  1.   apt install gravwell-netflow-capture
  2.   Point netflow to the Gravwell IP and Port in network_capture.conf

And that's really it.  I have an Ubiquiti EdgeRouterX at home; here's a quick setup of netflow pointing to Gravwell if needed: https://asciinema.org/a/343399)

Network Capture (PCAP) Ingester Install

This process is also easy and breaks down as follows:

  1.   apt install gravwell-network-capture
  2.   Check out network_capture.conf

In my lab I have a whole bunch of Internet of Sh!t traffic SPAN'd to ens192.  Which makes for some fun queries and dashboards!

Here's a quick video tying it all together:

 

In Part 3, we'll do a quick walk-through and check out all that sweet sweet data.  If you'd like to follow along and see how Gravwell can empower you on your analytical journey, It's as easy as signing up for the community edition and giving it a try. 

If you ever need help or want to talk use cases click the button below:


Query Questions?

Until next time!

 

Topics: ingester, HOWTO, setup, netflow, pcap

Ron Fabela

Written by Ron Fabela

Loves ICS, brewing and dissecting data.