Logstash: Data Processing Unit: SOC Level 2 : TryHackme

Опубликовано: 27 Июль 2026
на канале: Techby Anmol
430
6

🎥 Title Suggestion:
🔍 SOC Level 2: Logstash Data Processing | TryHackMe Full Walkthrough

📝 Description:

Welcome to another SOC Level 2 TryHackMe walkthrough!
In this video, I take you through the full Logstash Data Processing Unit room, where we install and configure the ELK stack (Elasticsearch, Logstash, Kibana), write Logstash configurations, and understand how data flows through input–filter–output stages.

I’ve already completed this room and cut down unnecessary parts, so you can get the maximum value in less time.

👉 Don't forget to like, comment your thoughts, and subscribe for more cybersecurity
⏱️ Timestamps:
00:00 - Intro and what this video covers
01:00 - Overview of ELK stack
02:50 - Installing Elasticsearch
08:00 - Verifying and configuring Elasticsearch
13:00 - Editing elasticsearch.yml
16:00 - Troubleshooting installation issues
19:20 - Reinstalling Elasticsearch
24:00 - Checking default port and version
29:15 - Installing Logstash
32:30 - Enabling and configuring Logstash
34:00 - Editing logstash.yml
36:00 - Installing Kibana
37:50 - Enabling and configuring Kibana
40:40 - Accessing Kibana in browser
42:00 - Enrollment token and authentication setup
48:30 - Kibana verification
49:30 - Logstash plugin overview
51:00 - Input, filter, and output plugin examples
56:10 - Writing Logstash configuration files
1:00:45 - More input plugin examples (TCP, HTTP, File, Beats)
1:04:00 - Filter plugin walkthrough (mutate, grok, prune, kv, etc.)
1:10:40 - Output plugin overview (Elasticsearch, file, RabbitMQ, stdout)
1:13:30 - Running Logstash configurations
1:18:30 - Real examples: STDIN, CSV, parsing auth.log
1:21:00 - Final thoughts and what's next