Kippo2ElasticSearch

Kippo2ElasticSearch is a Python script to transfer data from a Kippo SSH honeypot MySQL database to an ElasticSearch instance (server or cluster). This is useful in terms of indexing and searching the dataset and makes easy to visualize important stats using Kibana.

The project also provides an exported Kibana dashboard file that you can import to your own instance and get immediate visualization results from your honeypot data. The two sample screenshots below show a portion of that dashboard with data pulled from the following honeypot test articles:

DOWNLOAD Kippo2ElasticSearch:

Kippo2ElasticSearch depends on the following Python modules: GeoIP, pony, pyes. Installing these is trivial via pip.

SCREENSHOTS (Kibana):


Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Powered by WordPress and the Graphene Theme.

Read previous post:
Transferring Kippo’s data to ElasticSearch
Kippo-Graph 0.9.3 released, with new component: �Kippo-IP�
Kippo-Graph 0.9.2, with Kippo-Playlog!
Bypassing �clang: error: unknown argument�
Using KeePass on Mac OS X
Close