Skip to main content

BriefCam Installation Guide

Deploying a Graylog Server

Last Updated: 5 minute read
Version2024r2
LanguageEnglish

For large scale deployments, BriefCam recommends using the Graylog log management platform to collect the various logs into a single place to help debug the system.

To deploy a Graylog server you need a dedicated Linux server.

When you carry out all the steps below, the following internal components that are needed for Graylog to run will be installed:

  • MongoDB – A separate database instance for this purpose.

  • ElasticSearch – This is a middle layer through which the database and Graylog communicate.

  • Graylog

In addition, as part of the installation, an agent is deployed on each one of the BriefCam servers. The agent will be responsible for sending logs to the Graylog server.

Graylog histogram.png

Prerequisites

  • BriefCam is already deployed on your site.

  • The Linux server must be reachable from all BriefCam machines via HTTP/TCP.

Platform Requirements

The Linux server must be ubuntu 18.04.* LTS with the following specifications:

  • 1 x i7-10700K CPU

  • 64GB RAM

  • 256GB SSD

Other Requirements

  • All operations need to be performed by a user with sudo permissions.

Installing Graylog on the Linux Server

Installing Graylog on the Linux server consists of the following steps:

Step 1: Check that SSH Is Installed and Enabled
  1. Log into the Linux server.

  2. Open a terminal window.

  3. Issue the following commands:

    sudo apt update sudo apt install openssh-server 

  4. Check that the ssh daemon (service) is up and running:

    sudo systemctl status ssh

  5. You should see text similar to this: Active: active (running) :

  6. Type q to return to the console.

  7. Allow ssh in the firewall:

    sudo ufw allow ssh

  8. Terminate the shell session:

    sudo ufw allow ssh

Step 2: Install Docker Runtime

To install Docker Runtime:

  1. Open the SSH session to the server machine:

    ssh jjcale@tulsa-sound or jjcale@{Server IP address}

  2. Enter your password to connect to the SSH session.

  3. Update the apt package manager:

    sudo apt-get update 

  4. Install docker general dependencies:

    sudo apt-get install apt-transport-https ca-certificates curl gnupg-agent software-properties-common 

  5. Install a docker runtime PGP key:

    curl -fsSLhttps://download.docker.com/linux/ubuntu/gpg | sudo apt-key add – 

  6. Add a docker runtime repository:

    sudo add-apt-repository \ "deb [arch=amd64] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" 

  7. Install the docker run time itself and direct dependencies:

    sudo apt-get update sudo apt-get install docker-ce docker-ce-cli containerd.io 

  8. Test the docker installation. This should produce a short hello message to the console without errors:

    sudo docker run hello-world 

The output will look similar to the following:

Unable to find image 'hello-world:latest' locally latest: Pulling from library/hello-world 0e03bdcc26d7: Pull complete Digest: sha256:e7c70bb24b462baa86c102610182e3efcb12a04854e8c582838d92970a09f323 Status: Downloaded newer image for hello-world:latestHello from Docker! This message shows that your installation appears to be working correctly. 

  1. Add the 'docker' user to the group of the user you are logged in with:

    sudo usermod -aG docker jjcale 

  2. Make sure to log out or exit the current session in order for the usermod command to take effect.

  3. Install docker-compose runtime:

    sudo curl -L "https://github.com/docker/compose/releases/download/1.27.4/docker-compose-$(uname -s)-$(uname-m)" -o /usr/local/bin/docker-compose 

  4. Give docker-compose execution permissions:

    sudo chmod +x /usr/local/bin/docker-compose 

Step 3: Copy and Extract the Installation Files
  1. Copy the files from the machine that hosts the installation file (usually a Windows machine) to the Linux server.

  2. Use openssh for Windows or winscp: https://winscp.net/download/WinSCP-5.17.9-Setup.exe

  3. Run: scp path\to\package\server.zip jjcale@192.168.0.3:/home/jjcale/

  4. ssh to the server machine and extract the package files:

    cd ~

    unzip server.zip

    cd server

Step 4: Configure and Activate the Graylog Server Engine
  1. Open the docker-compose-graylog.yml file with a text editor and set:

    GRAYLOG_HTTP_EXTERNAL_URI=server_ip 

  2. Leave the port as is. For example:

    GRAYLOG_HTTP_EXTERNAL_URI=http ://{Server IP address}:9000/ 

  3. Create a directory for the Graylog files:

    sudo mkdir-p /opt/briefcam/graylog 

  4. Copy the Graylog compose file to the newly created directory:

    sudo cp docker-compose-graylog.yml /opt/briefcam/graylog/ 

  5. Create a Graylog service by copying graylog-docker.service to /etc/systemd/system:

    sudo cp graylog-docker.service /etc/systemd/system/ 

  6. Enable the new service for when the machine is restarted:

    sudo systemctl daemon-reload sudo systemctl enable graylog-docker 

  7. Start the Graylog service:

    sudo systemctl start graylog-docker 

Note

The first start may take a couple of minutes since the pulling and starting of new docker containers takes some time.

Step 5: Configure Graylog Collectors
  1. Log into the Graylog web interface.

  2. Open a browser and go to the following address: http://{Server IP address}:9000

  3. The credentials are:

    user: admin

    password: admin

  4. Go to system/inputs.

  5. Create GELF TCP input:

    1. Check the Global checkbox.

    2. Add a title, such as: "Win TCP".

    3. Set the port to 12201 (the default).

  6. Create GELF UDP input:

    1. Check the Global checkbox.

    2. Add a title, such as: "Win UDP".

    3. Set the port to 12201 (the default).

  7. Go to system/sidecars.

  8. Create an API token.

    1. Click Create or reuse a token for the graylog-sidecar user.

    2. Add a token name, such as: "Win token".

    3. Click Create Token.

  9. Save the token or copy it to the clipboard.

Step 6: Configure BriefCam Servers to Send Logs to the Graylog Server

The following steps should be carried out on every BriefCam server.

Step a: Copy the Installation Package Files 

  • Log into the machine remotely (RDP) and copy the following files from the installation links to each of the BriefCam servers:

    graylog_sidecar_installer_1.0.2-1.exe 

    nxlog-ce-2.10.2150.msi 

    windows_exporter-0.14.0-amd64.msi 

Step b: Install the Logs Collector 

  1. Install the nxlog collector by running the following in PowerShell with elevated administrative permissions:

    ..\nxlog-ce-2.10.2150.msi/qn 

  2. The first step creates services on your machine. In this step, you need to deactivate the system services (Graylog only needs the binaries) by running the following in PowerShell:

    cd 'C:\Program Files (x86)\nxlog\'.\nxlog.exe-u 

  3. Install the Graylog sidecar as a service with the Graylog server IP and the saved API token by running the following in PowerShell:

    .\graylog_sidecar_installer_1.0.0-1.exe/S-SERVERURL="http://{Server IP address }:9000/api"-APITOKEN="<api-token>" 

Step c: Configure the Sidecar 

  1. Edit the C:\Program Files\Graylog\sidecar\sidecar.yml file and uncomment the following entries:

    • cache_path 

    • log_path 

    • collector_configuration_directory 

    • collector_binaries_whitelist and the accompanying'- "C:\\Program Files (x86)\\nxlog\\nxlog.exe"' entry

  2. Save the file.

  3. Register the sidecar as a service and start it by issuing the following commands from the C:\Program Files\Graylog\sidecar directory:

    C:\Program Files\Graylog\sidecar> .\graylog-sidecar.exe -service install 

    C:\Program Files\Graylog\sidecar> .\graylog-sidecar.exe -service start 

Step d: Create the Graylog Configuration 

  1. Open the Graylog UI and navigate to system/sidecars.

  2. Find your connected machine and click manage sidecar.

  3. Select the nxlog checkbox.

  4. Click Configuration.

  5. Under log collectors, click edit in the nxlog Windows version.

  6. Give a name, such as "win-nxlog".

  7. In the default template section, update File entry in the <Input file> section to the desired log directory.

  8. In the <Output gelf> section, set the Host IP to the correct connected machine address (Server IP address)

  9. Click Update.