[{"id": 15138, "state": 1, "location": "Room 9", "location_slug": "room_9", "sequence": 16, "name": "Behind the scenes of an ELK system", "slug": "Behind_the_scenes_of_an_ELK_system", "authors": "Rafael Martinez Guerrero", "description": "Behind every security measure you take, you should have an information management system helping you take decisions.\r\n\r\nIf you work with security, you need a way to collect, process, save and analyze huge amounts of data that should be used to control how your systems are behaving, find anomalies and evaluate the results of your actions.\r\n\r\nHave you ever wondered how to manage billions of logs and metrics from thousands of devices in your infrastructure? If you need high-availability and a resilient and stable system to process your data this is the tutorial for you. \r\n\r\nBased on the experience obtained in the past 4 years at the University of Oslo processing billions of logs a day from more than 15000 devices, this tutorial will give some inside information and many tips about how to achieve this with Linux and open source software.\r\n\r\nYou will learn how to put together HAProxy, agents, Logstash, Elasticsearch and RabbitMQ to work at scale. You will also hear about the problems and pitfalls we have experienced during these years and what we learned from them.", "start": "2020-01-17T16:45:00Z", "duration": "0:100:0", "released": true, "license": "CC BY", "tags": null, "conf_key": "72", "conf_url": "https://lca2020.linux.org.au/schedule/presentation/82/", "host_url": null, "public_url": null, "rax_mp4_url": null, "archive_url": null, "archive_mp4_url": "", "twitter_url": null, "comment": "", "start_at": "16:40 17.01.2020"}]