ELK Stack Dashboards
deviceTRUST includes components for an ELK Stack to easily create a dashboard to monitor the contextual status of your remoting and DaaS environment.
The License Compliance Templates can be used with your ELK Stack to monitor or enforce Device-Based Licensing requirements for one or more applications:
data:image/s3,"s3://crabby-images/350b6/350b6a9c2b99169a9707cbc3ef3f889857d62026" alt="The Device-Based Licensing dashboard"
The ELK Stack Status Report Template can be used to monitor the status of your remoting and DaaS environment:
data:image/s3,"s3://crabby-images/f2910/f2910b3fa9a8fd873d7abba56d5e19ea3fdd0cf3" alt="The Status Report dashboard"
Step 1: Components
The deviceTRUST dashboards for ELK Stack consist of several components. All elements that need to be imported on the ELK Stack side can be found on GitHub. The configuration for the deviceTRUST Agent is available as a template within the deviceTRUST Console.
Step 1.1: Components - GitHub
All required components for ELK Stack can be found on our GitHub repository.
- Saved objects for ELK are not backward compatible. Please use only versions matching or older than your system.
- Select the version number matching your ELK Stack system and download the files. You can of course also clone the whole repository if you like.
data:image/s3,"s3://crabby-images/9758b/9758b3330204b252e29a849a412a67298b5d7937" alt="Downloading the ELK Stack components"
Every version folder contains folders for each use case. Each of these use case folders contains the relevant stored object and mapping files.
data:image/s3,"s3://crabby-images/2ab3e/2ab3e033d3e7421a0f6c7a8ad92f736e4b55e922" alt="The use case folders within the versioned ELK Stack"
Each use case folder contains the following files:
-
elkstack-<use case>-mappings.txt
contains data definitions for the data being sent to ELK Stack index mapping. -
elkstack-<use case>-saved-objects.ndjson
contains all objects that are required to store, search and visualize data, such as indexes, scripted fields, dashboards and searches.
data:image/s3,"s3://crabby-images/e0de7/e0de705afc28caf146701583c14e27f9813be268" alt="The ELK Stack files to implement the use case"
Step 1.2: Components - Templates
deviceTRUST must be configured to send the required data for each use case. Templates for both use cases are included in the deviceTRUST Console.
data:image/s3,"s3://crabby-images/5f6e6/5f6e6d438663a4a90939da37b3077ad8599b749f" alt="The Status Report category of templates"
Step 2: The Device-Based Licensing Report
This part of the guide relates to Device-Based Licensing
. It lists all steps that are required to configure the ELK Stack, and also how to configure the deviceTRUST Agent.
Step 2.1: Add Index Template to ELK Stack
The first step is to create an Index Template
. Index Templates describe the data that is being sent to an index. They make sure that every date is treated according to its type.
- Within the ELK Stack management console, navigate to
Menu\Stack Management\Index Management\Index Templates
. - Click
Create Template
.
data:image/s3,"s3://crabby-images/05ff7/05ff7f584c67a9efc691a188fd13851f5000b497" alt="Creating an Index Template within your ELK Stack"
- Set
Name
todt_devicebasedlicensing
. - Set
Index Patterns
todt_devicebasedlicensing*
.
data:image/s3,"s3://crabby-images/7117e/7117e6fcdce279305275536ab3dfe790ca4e8f6b" alt="Configuring the Index Template"
- Skip all options until
Mappings
. - Select
Load Json
to import the fileelkstack-device-based-licensing-mappings.txt
that was downloaded in Step 1.1.
data:image/s3,"s3://crabby-images/37de5/37de583a1c957aea38efc42a7a8b5a23b5515dd0" alt="Importing the mappings file"
- Proceed with
Load and overwrite
.
data:image/s3,"s3://crabby-images/feda3/feda38b3485f736b243527819f4ffbd644d18a75" alt="Loading the mappings file"
The imported mappings are displayed. Please review them carefully.
-
SessionDate
needs to be recognized as typeDate
for the report to function properly.
data:image/s3,"s3://crabby-images/c971b/c971b8160a22841ca33cd866f45374c820acff4f" alt="Reviewing the mappings"
- Skip all options until
Review Template
. - Generate the template with
Create Template
.
data:image/s3,"s3://crabby-images/1b390/1b39018cde17df58ddd80a3aaf49c87eb289ef93" alt="Creating the template"
You’ll be given an overview of the created template. A blue marked M
in the Content
section indicates that mappings are available.
data:image/s3,"s3://crabby-images/84b84/84b846271ede9b30c7cb8d1eae8ede3b7c0ad69c" alt="The created index template"
Step 2.2: Import Saved Objects to ELK Stack
All other parts of the report are to be imported as Saved Objects
. The Saved Objects consist of Index Patterns with Scripted Fields, Visualizations and Dashboards.
- Navigate to
Menu\Stack Management\Saved Objects
in your ELK Stack management console. - Click
Import
.
data:image/s3,"s3://crabby-images/95e34/95e34f9e7dcce785bd7277fa57a8ab98200cc4d2" alt="Importing the Saved Objects"
- Select the file
elkstack-device-based-licensing-saved-objects.ndjson
. - Check
Create new objects with random IDs
to make sure no existing objects are altered.
data:image/s3,"s3://crabby-images/6bb11/6bb11c461e19904814597f49c0e2d9c83fe160a7" alt="Importing the Saved Objects"
After importing, an overview of the imported objects will be displayed.
data:image/s3,"s3://crabby-images/4746d/4746d2f08ea03d49ea28678fee2dc4a25c886ee6" alt="Overview of the Saved Objects"
Step 2.3: Configuring deviceTRUST
After the Index Mapping has been created and the Saved Objects are included, the ELK Stack is prepared for storing, sorting, and displaying your data.
The final step is to create the deviceTRUST configuration that will make sure all the required data is provided.
- Open the
deviceTRUST Console
. - Click
Sharing
in the top right menu. You may need to clickShow Advanced View
if this button is not visible.
data:image/s3,"s3://crabby-images/93d9d/93d9dc15a596a982fe00b38c1a4ed3b24484a4bf" alt="The Sharing button"
- Select
Import Template
.
data:image/s3,"s3://crabby-images/3ad76/3ad76e0eaa10641f4b4a93da544ad8e8173d9e0c" alt="Importing the template"
- For
Device-Based Licensing
, the template categoryLicense Compliance
is used.
data:image/s3,"s3://crabby-images/bed55/bed55f46bc00246f4d24c1fff3d995d89d9c310b" alt="The License Compliance template category"
This category contains templates for several software products. This example uses Acrobat DC
, but can easily be customised for other applications.
data:image/s3,"s3://crabby-images/89b70/89b702efb912904ef3882013c91a387f3f78352f" alt="The Acrobat DC template"
Two contexts are included:
-
Adobe Acrobat DC Licensed Status
to evaluate the device’s license status. -
Adobe Acrobar DC User
to define if the accessing user shall or shall not be using the software.
data:image/s3,"s3://crabby-images/c9e80/c9e80977ee34e56841f98848403f18d891ac29e1" alt="The contexts within the Acrobat DC template"
Three actions are included:
-
Adobe Acrobat DC Licensed Device - Conditional Application Access - FSLogix App Masking
is used for controlling access to the software using FSLogix App Masking. This action can be ignored or removed for now. -
Adobe Acrobat DC Licensed Device - Conditional Application Access - Microsoft AppLocker
is used for controlling access to the software using Microsoft Applocker. This action can be ignored or removed for now. -
Adobe Acrobat DC Licensed Device - Conditional Application Access - Reporting
is the only action required for reporting.
data:image/s3,"s3://crabby-images/a458d/a458df463191bbe3a26538539c5d3ce009e152d3" alt="The actions within the Acrobat DC template"
- The action contains multiple ways to store the data. Sending data to ELK Stack is configured by using a
Web Request
task. TheAudit Event
,Custom Process
, as well as theWeb Request
Tasks for Splunk and Graylog can be deleted, as we are looking at ELK Stack here.
data:image/s3,"s3://crabby-images/530b1/530b1dd7699f93264fcb143b716fa8855fe2430c" alt="The actions within the Acrobat DC template"
- The Web Request task must be edited to suit your environment. If you use a basic setup without SSL or authorization, adding
your server’s fqdn
is the only required configuration change.
data:image/s3,"s3://crabby-images/692b8/692b850f0d6058c3cde9fecc5b749e90416b2327" alt="Customising the Web Request task"
After the index template has been created, the saved objects are imported and the agent-side has been configured, the use case Device-Based Licensing
has been implemented successfully.
deviceTRUST now sends status data about the application usage and the required hardware information to ELK Stack on every access to the remoting system. The data is presented in the created dashboards.
data:image/s3,"s3://crabby-images/350b6/350b6a9c2b99169a9707cbc3ef3f889857d62026" alt="The completed Device-Based Licensing Dashboard"
Step 3: The Status Report
This part of the guide relates to the Status Report
. It lists all steps that are required to configure the use case on the agent-side, as well as on the ELK Stack side.
Step 3.1: Add Index Template to ELK Stack
The first step is to create an Index Template
. Index Templates describe the data that is being sent to an index. They make sure, that every date is treated according to its type.
- Within the ELK Stack management console, navigate to
Menu\Stack Management\Index Management\Index Templates
. - Click
Create Template
.
data:image/s3,"s3://crabby-images/05ff7/05ff7f584c67a9efc691a188fd13851f5000b497" alt="Creating an Index Template within your ELK Stack"
- Set
Name
todt_statusreport
. - Set
Index Patterns
todt_statusreport*
.
data:image/s3,"s3://crabby-images/dfe02/dfe02e079e83302c49d8ed753d7ebbcb1695deb9" alt="Configuring the Index Template"
- Skip all options until
Mappings
. - Select
Load Json
to import theelkstack-status-report-mappings.txt
that was downloaded in Step 1.1.
data:image/s3,"s3://crabby-images/37de5/37de583a1c957aea38efc42a7a8b5a23b5515dd0" alt="Importing the mappings file"
- Proceed with
Load and overwrite
.
data:image/s3,"s3://crabby-images/2cce8/2cce88819b402983988b6a86e2f5fe1139bd504f" alt="Loading the mappings file"
- The imported mappings are displayed. Please review them carefully.
Session Date
,Anti-Virus Timestamp
andHardware BIOS Release Date
need to be recognized as typeDate
for the report to function properly.
data:image/s3,"s3://crabby-images/1635c/1635cca9e8ede7206ac32d7a81d7da05ba3cb5c1" alt="Reviewing the mappings"
- Skip all options until
Review Template
. - Generate the template with
Create Template
.
data:image/s3,"s3://crabby-images/4a22c/4a22c9fd3215bd0b532fbcd6432b2424437a96df" alt="Creating the template"
- You’ll be given an overview of the created template. A blue marked
M
in theContent
section indicates, that mappings are available.
data:image/s3,"s3://crabby-images/f5ad4/f5ad4d60ab781571b574da5749e5580c93d25c60" alt="The created index template"
Step 3.2: Import Saved Objects to ELK Stack
All other parts of the report are to be imported as Saved Objects
. The Saved Objects consist of Index Patterns with Scripted Fields, Visualizations and Dashboards.
- Navigate to
Menu\Stack Management\Saved Objects
in your ELK Stack management console. - Click
Import
.
data:image/s3,"s3://crabby-images/95e34/95e34f9e7dcce785bd7277fa57a8ab98200cc4d2" alt="Importing the Saved Objects"
- Select the file
elkstack-status-report-saved-objects.ndjson
. - Check
Create new objects with random IDs
to make sure no existing objects are altered.
data:image/s3,"s3://crabby-images/03c3a/03c3af3189340d41190bf1a35684c94c886c48cb" alt="Importing the Saved Objects"
After importing, an overview of the imported objects will be displayed.
data:image/s3,"s3://crabby-images/e2824/e28246b8b854c2f561d8743ca77ebbc67fcc813a" alt="Overview of the Saved Objects"
Step 3.3: Configuring deviceTRUST
After the Index Mapping has been created, the Saved Objects are included the index has been edited and the agent-side has been configured, the ELK Stack is prepared for storing, sorting, and displaying your data.
The last step is to create the deviceTRUST configuration, that will make sure all required data is provided.
- Open the
deviceTRUST Console
. - Click
Sharing
in the top right menu. You may need to clickShow Advanced View
if this button is not visible.
data:image/s3,"s3://crabby-images/93d9d/93d9dc15a596a982fe00b38c1a4ed3b24484a4bf" alt="The Sharing button"
- Select
Import Template
.
data:image/s3,"s3://crabby-images/3ad76/3ad76e0eaa10641f4b4a93da544ad8e8173d9e0c" alt="Importing the template"
- For
Status Report
, the template categoryStatus Report
is used.
data:image/s3,"s3://crabby-images/13d7f/13d7fc946824254e466f7344b5f47b837663a6e1" alt="The Status Report template category"
- This category contains templates for several ways of storing data. Choose
ELK Stack
.
data:image/s3,"s3://crabby-images/c720e/c720e4e4d059f1794ce9e892df2f87a7d2542795" alt="The ELK Stack for Remoting template"
- The imported template consists of 50 contexts and one action.
- The Action
Status Report – ELK Stack
collects all relevant data and sends them over to the ELK Stack.
data:image/s3,"s3://crabby-images/b90e5/b90e5b62309cd13b7c6a72b698ea676c29f227aa" alt="The Status Report - ELK Stack action"
- Sending data to ELK Stack is configured by using a
Web Request
task.
data:image/s3,"s3://crabby-images/82aec/82aec6f907f8cf64d4671e1afd27b308ffedd45b" alt="The Web Request task used to send data to the ELK Stack"
- The Web Request task must be edited to suit your environment. If you use a basic setup without SSL or authorization, simply adding your
server’s fqdn
will do.
data:image/s3,"s3://crabby-images/8db27/8db272f70a02fcd4f96d75260843a5f55feeed9a" alt="Customising the Web Request task"
Step 3.4: Edit index settings
For the Status Report Dashboards to work properly, a configuration needs to be made at the index level: In a basic setting, ELK Stack allows to use 25 “calculated fields” per index. For the Status Report Dashboard, 48 calculated fields are used. Thus, the allowed number of calculated fields
needs to be set to a higher value.
data:image/s3,"s3://crabby-images/eebb8/eebb8d0afcdff53667dc7f8d44af38f14eae1971" alt="An error displayed when the allowed number of calculated fields is exceeded"
You need to send data to ELK Stack first. Sending data will create the index with basic settings. It can then be edited.
- After sending your first data, you will find the index
dt_statusreport
has been created in the Index Management Menu.
data:image/s3,"s3://crabby-images/c446a/c446a3cf4eea5158bff1ff07eef099d9e32478e8" alt="The created dt_statusreport within the Index Management"
- Select the Index and chose
Edit Settings
. You’ll be presented a json configuration view.
data:image/s3,"s3://crabby-images/ff042/ff04295d4e6b2a47e0b3f8cd83c198983ac5b504" alt="Editing the index"
- Add
"index.max_script_fields": "50"
as a new line, making sure to keep the correct json formatting. - Save your changes.
data:image/s3,"s3://crabby-images/e0433/e043326a56e5122fc5d93da17c7877360e84c62e" alt="The created dt_statusreport within the Index Management"
Your Dashboard will now be displayed without errors.
After the index template has been created and the saved objects are imported, the use case Status Report
has been implemented successfully.
deviceTRUST now sends status data to ELK Stack on every access to the remoting system. The data is presented in the created dashboards.
data:image/s3,"s3://crabby-images/f2910/f2910b3fa9a8fd873d7abba56d5e19ea3fdd0cf3" alt="The completed Status Report dashboard"