<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="de">
	<id>https://wiki.ixheim.de/index.php?action=history&amp;feed=atom&amp;title=ELK_Kali_Purple_Installation</id>
	<title>ELK Kali Purple Installation - Versionsgeschichte</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.ixheim.de/index.php?action=history&amp;feed=atom&amp;title=ELK_Kali_Purple_Installation"/>
	<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=ELK_Kali_Purple_Installation&amp;action=history"/>
	<updated>2026-06-29T12:59:49Z</updated>
	<subtitle>Versionsgeschichte dieser Seite in Xinux Wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://wiki.ixheim.de/index.php?title=ELK_Kali_Purple_Installation&amp;diff=52829&amp;oldid=prev</id>
		<title>Thomas.will: Die Seite wurde neu angelegt: „=Install elasticsearch= *sudo apt update &amp;&amp; sudo apt upgrade *sudo bash -c &quot;export HOSTNAME=purple.cyber.local; apt-get install elasticsearch -y&quot; '''take note…“</title>
		<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=ELK_Kali_Purple_Installation&amp;diff=52829&amp;oldid=prev"/>
		<updated>2024-04-12T10:15:14Z</updated>

		<summary type="html">&lt;p&gt;Die Seite wurde neu angelegt: „=Install elasticsearch= *sudo apt update &amp;amp;&amp;amp; sudo apt upgrade *sudo bash -c &amp;quot;export HOSTNAME=purple.cyber.local; apt-get install elasticsearch -y&amp;quot; &amp;#039;&amp;#039;&amp;#039;take note…“&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Neue Seite&lt;/b&gt;&lt;/p&gt;&lt;div&gt;=Install elasticsearch=&lt;br /&gt;
*sudo apt update &amp;amp;&amp;amp; sudo apt upgrade&lt;br /&gt;
*sudo bash -c &amp;quot;export HOSTNAME=purple.cyber.local; apt-get install elasticsearch -y&amp;quot;&lt;br /&gt;
'''take note of &amp;quot;elastic&amp;quot; user password'''&lt;br /&gt;
;Example: The generated password for the elastic built-in superuser is : '''jYu2XsCOAbI6IXicyt60'''&lt;br /&gt;
;Reset:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
You can complete the following actions at any time:&lt;br /&gt;
&lt;br /&gt;
Reset the password of the elastic built-in superuser with &lt;br /&gt;
'/usr/share/elasticsearch/bin/elasticsearch-reset-password -u elastic'.&lt;br /&gt;
&lt;br /&gt;
Generate an enrollment token for Kibana instances with &lt;br /&gt;
 '/usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s kibana'.&lt;br /&gt;
&lt;br /&gt;
Generate an enrollment token for Elasticsearch nodes with &lt;br /&gt;
'/usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s node'.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Convert to single-node setup (or replace fqdn name in initial_master_nodes list with IP address)=&lt;br /&gt;
+*sudo sed -e '/cluster.initial_master_nodes/ s/^#*/#/' -i /etc/elasticsearch/elasticsearch.yml&lt;br /&gt;
*echo &amp;quot;discovery.type: single-node&amp;quot; | sudo tee -a /etc/elasticsearch/elasticsearch.yml&lt;br /&gt;
=Install Kibana=&lt;br /&gt;
*sudo apt install kibana&lt;br /&gt;
==Add keys to /etc/kibana/kibana.yml==&lt;br /&gt;
*sudo /usr/share/kibana/bin/kibana-encryption-keys generate -q&lt;br /&gt;
;Created Kibana keystore in /etc/kibana/kibana.keystore&lt;br /&gt;
 xpack.encryptedSavedObjects.encryptionKey: eb4257cb863d2cf1c5dc04494a2d5122&lt;br /&gt;
 xpack.reporting.encryptionKey: 82a7f97e18d6946bb81762eb4b945b93&lt;br /&gt;
 xpack.security.encryptionKey: 0c7aeeef3764088b4048d40b82409f38&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*echo &amp;quot;server.host: \&amp;quot;purple.cyber.local\&amp;quot;&amp;quot; | sudo tee -a /etc/kibana/kibana.yml&lt;br /&gt;
&lt;br /&gt;
=Anpassungen=&lt;br /&gt;
;Ans Ende&lt;br /&gt;
 /etc/kibana/kibana.yml&lt;br /&gt;
 server.port: 5601&lt;br /&gt;
 server.host: &amp;quot;0.0.0.0&amp;quot;&lt;br /&gt;
==Ensure kali-purple.kali.purple is only mapped to 192.168.253.5 in /etc/hosts in order to bind Kibana to that interface==&lt;br /&gt;
*sudo systemctl enable elasticsearch kibana --now&lt;br /&gt;
&lt;br /&gt;
=Enroll Kibana=&lt;br /&gt;
*sudo /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s kibana&lt;br /&gt;
 #open browser and navigate to http://192.168.253.5:5601 enter username=elastic and password as displayed after installation paste token from above&lt;br /&gt;
*sudo /usr/share/kibana/bin/kibana-verification-code&lt;br /&gt;
 #enter verification code into Kibana when prompted&lt;br /&gt;
&lt;br /&gt;
=Enable HTTPS for Kibana=&lt;br /&gt;
*sudo /usr/share/elasticsearch/bin/elasticsearch-certutil ca&lt;br /&gt;
*sudo /usr/share/elasticsearch/bin/elasticsearch-certutil cert --ca elastic-stack-ca.p12 --dns purple.cyber.local,elastic.cyber.local,purple --out kibana-server.p12&lt;br /&gt;
*sudo openssl pkcs12 -in /usr/share/elasticsearch/elastic-stack-ca.p12 -clcerts -nokeys -out /etc/kibana/kibana-server_ca.crt&lt;br /&gt;
*sudo openssl pkcs12 -in /usr/share/elasticsearch/kibana-server.p12 -out /etc/kibana/kibana-server.crt -clcerts -nokeys&lt;br /&gt;
*sudo openssl pkcs12 -in /usr/share/elasticsearch/kibana-server.p12 -out /etc/kibana/kibana-server.key -nocerts -nodes&lt;br /&gt;
*sudo chown root:kibana /etc/kibana/kibana-server_ca.crt&lt;br /&gt;
*sudo chown root:kibana /etc/kibana/kibana-server.key&lt;br /&gt;
*sudo chown root:kibana /etc/kibana/kibana-server.crt&lt;br /&gt;
*sudo chmod 660 /etc/kibana/kibana-server_ca.crt&lt;br /&gt;
*sudo chmod 660 /etc/kibana/kibana-server.key&lt;br /&gt;
*sudo chmod 660 /etc/kibana/kibana-server.crt&lt;br /&gt;
&lt;br /&gt;
*echo &amp;quot;server.ssl.enabled: true&amp;quot; | sudo tee -a /etc/kibana/kibana.yml&lt;br /&gt;
*echo &amp;quot;server.ssl.certificate: /etc/kibana/kibana-server.crt&amp;quot; | sudo tee -a /etc/kibana/kibana.yml&lt;br /&gt;
*echo &amp;quot;server.ssl.key: /etc/kibana/kibana-server.key&amp;quot; | sudo tee -a /etc/kibana/kibana.yml&lt;br /&gt;
*echo &amp;quot;server.publicBaseUrl: \&amp;quot;https://purple.cyber.local:5601\&amp;quot;&amp;quot; | sudo tee -a /etc/kibana/kibana.yml&lt;br /&gt;
&lt;br /&gt;
*sudo /usr/share/kibana/bin/kibana-encryption-keys generate&lt;br /&gt;
 #Copy the generated keys into /etc/kibana/kibana.yml&lt;br /&gt;
&lt;br /&gt;
*sudo systemctl restart kibana&lt;br /&gt;
&lt;br /&gt;
=Links=&lt;br /&gt;
*https://gitlab.com/kalilinux/kali-purple/documentation/-/wikis/301_31:-Elastic-Stack-Installation&lt;/div&gt;</summary>
		<author><name>Thomas.will</name></author>
	</entry>
</feed>