Skip to content

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

2 watching

Forks

Repository files navigation

ansible-role-tpotce-filebeat

Ships T-Pot honeypot logs with Filebeat. Use it alongside honeynet/ansible-role-tpotce, which starts the Filebeat container; add filebeat to that role's tpot_services so the container is generated.

This role writes configuration only. It does not install or run Filebeat.

What it configures

  • {{ filebeat_path }}/filebeat.yml — the main configuration, including the output transport.
  • {{ filebeat_path }}/conf.d/<honeypot>.yml — one input per entry in honeypot_list. Files for honeypots no longer selected are removed, because Filebeat globs the directory rather than reading honeypot_list.

The inputs mirror the input section of upstream's docker/elk/logstash/dist/logstash.conf for T-Pot 24.04, so every log file upstream reads directly is shipped here instead. Each input sets:

  • tags: ["<honeypot>"] — what the Logstash filters key on.
  • type: <Type> — the same capitalised type name upstream uses, carried as a root field so downstream configuration can match upstream's [type] tests.
  • t-pot_ip_ext, t-pot_ip_int, t-pot_hostname from the container environment, replacing the ${MY_EXTIP} interpolation upstream does inside Logstash.

Requirements

Filebeat 9.x. The inputs use the filestream type; the log input they previously used was deprecated in 7.16 and removed in 9.0. The companion image honeynet/filebeat tracks the Elasticsearch version pinned by upstream T-Pot.

Role variables

Transport

Exactly one output transport is active, selected by filebeat_output:

Variable Default Description
filebeat_output logstash logstash or kafka.

logstash

Variable Default Description
logstash_servers 127.0.0.1:5044 A host:port string or a list of them.
filebeat_logstash_loadbalance true Spread events across all hosts.
filebeat_logstash_compression_level 3 gzip level, 0–9.

kafka

Events are routed to one topic per honeypot, named <filebeat_kafka_topic_prefix><honeypot> — cowrie lands in tpot-cowrie. Routing keys off the tag each input sets, so it stays in step with honeypot_list automatically.

Variable Default Description
filebeat_kafka_hosts [] Broker list. Required for this transport.
filebeat_kafka_topic_prefix tpot- Prefix for the per-honeypot topics.
filebeat_kafka_topic_fallback tpot-unrouted Catches events matching no honeypot tag, which would otherwise be dropped silently.
filebeat_kafka_version 2.6.0 Oldest broker in the cluster.
filebeat_kafka_required_acks 1 0 none, 1 leader, -1 all replicas.
filebeat_kafka_compression gzip none, snappy, lz4 or gzip.
filebeat_kafka_partition_strategy hash random, round_robin or hash.
filebeat_kafka_max_message_bytes 1000000 Must not exceed the broker's message.max.bytes.
filebeat_kafka_username / _password "" Set the username to enable SASL.
filebeat_kafka_sasl_mechanism SCRAM-SHA-512 Ignored unless a username is set.
filebeat_kafka_ssl_enabled false TLS to the brokers.
filebeat_kafka_ssl_certificate_authorities [] CA bundles for the above.

Everything else

Variable Default Description
filebeat_path /opt/filebeat/etc Where the configuration is written. Must match what the container mounts.
honeypot_list all 34 upstream sources Honeypots to ship. Each entry needs a matching files/conf.d/<name>.yml; the role fails early if one is missing.

Example

Shipping a subset to a pair of Logstash hosts:

- hosts: sensors
  roles:
    - role: ansible-role-tpotce-filebeat
      vars:
        logstash_servers:
          - "logstash1.example.org:5044"
          - "logstash2.example.org:5044"
        honeypot_list: [cowrie, dionaea, heralding, suricata]

Shipping everything to Kafka over TLS:

- hosts: sensors
  roles:
    - role: ansible-role-tpotce-filebeat
      vars:
        filebeat_output: kafka
        filebeat_kafka_hosts: ["kafka1.example.org:9093", "kafka2.example.org:9093"]
        filebeat_kafka_ssl_enabled: true
        filebeat_kafka_ssl_certificate_authorities: [/etc/pki/tls/certs/kafka-ca.crt]
        filebeat_kafka_username: honeynet
        filebeat_kafka_password: "{{ vault_kafka_password }}"

Testing

pip3 install -r requirements.txt
ansible-galaxy collection install -r requirements.yml

molecule test              # logstash transport
molecule test -s kafka     # kafka transport

Both scenarios render the configuration into a container and assert on the result; neither starts Filebeat.

To test another platform from the CI matrix, set all three variables together -- the image is a full reference, not a distribution slug:

MOLECULE_IMAGE=almalinux:10 MOLECULE_DISTRO_TAG=almalinux10 \
  MOLECULE_DOCKER_COMMAND=/usr/lib/systemd/systemd molecule test

CI runs both scenarios against the current release of each distribution honeynet/ansible-role-tpotce supports: debian13, ubuntu2604, almalinux10, rockylinux10, fedora44 and tumbleweed.

Special Thanks

This project is supported by:

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages