# Mastering Network Monitoring: How to Build a Modern NMS with Suricata, Elasticsearch, and Real-time Alerts

**What Is NMS?**

Network Management System (NMS) is a set of tools used to monitor, manage, and secure computer networks. By using NMS, network administrators can detect threats, identify performance issues, and take corrective actions proactively.

**Benefits of NMS?**

**Improved Network Security:**

* **Faster Threat Detection:** NMS can proactively monitor network traffic and detect anomalies or suspicious activities that indicate a cyber attack.
    
* **In-depth Log Analysis:** NMS can identify complex attack patterns and exploit unknown vulnerabilities by collecting and analyzing logs from various network devices.
    
* **Faster Response:** Instant threat notifications allow the security team to respond quickly to minimize the impact of an attack.
    

**Improved Network Performance:**

* **Real-time Performance Monitoring:** NMS provides comprehensive visibility into network performance, allowing quick identification of bottlenecks and other performance issues.
    
* **Resource Optimization:** With accurate performance data, administrators can optimize the use of bandwidth, CPU, and other resources.
    
* **Capacity Planning:** NMS assists in network capacity planning to meet the growing needs of the business.
    

**Reduced Downtime:**

* **Proactive Detection:** NMS can detect potential issues before they become serious disruptions, thus reducing downtime.
    
* **Quick Problem Diagnosis:** With comprehensive data, administrators can quickly identify the root cause of issues and make repairs.
    

**Examples of NMS Use in Practice?**

* **DDoS Attack Detection:** NMS can detect unusual traffic spikes indicating a DDoS attack.
    
* **Application Performance Monitoring:** NMS can monitor application response times and identify performance issues affecting users.
    
* **Traffic Trend Analysis:** NMS can analyze network traffic trends to identify usage patterns and anticipate future bandwidth needs.
    

## **Installation and Configuration of NMS with Suricata, ELK Stack, and Filebeat**

### **Prerequisites**

Before starting the installation, ensure that we have a stable operating system that meets the following requirements:

* **Operating System:** Prepare a server for NMS, a client, and Kali Linux for attacking the NMS server.
    
* **Root Access:** We need root access or a user with sudo privileges to run installation commands.
    
* **Network:** Ensure our system is connected to the network and has internet access to download necessary packages.
    

### **Installation and Initial Configuration of Suricata**

1. Setup for installing a stable version of Suricata.
    
    ```abap
    apt-update
    apt-get install software-properties-common
    add-apt-repository ppa:oisf/suricata-stable
    apt update
    "If so, you can install Suricata"
    apt-get install suricata
    ```
    
2. Initial Configuration of Suricata
    

configuration of Suricata in /etc/suricata/suricata.yml

```abap
vim /etc/suricata/suricata.yml
```

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXcfk9giuKF1MsRBTXMTh9ZoaTrww1g700ZRgLlK3hzmPfFStu_4lt8eOMNxhm4o9RkJCv1fKK0sXDfCaBw2LBk74uMFJL_lEsCLlcBV5YkHMie36klEbYm9wyz7nCrUuTkdeadNk48QIpsB9Ib_BWvYQDo?key=TAh-k7LROlAl0b85eOhptg align="center")

```abap
suricata-update
systemctl restart suricata
systemctl status suricata
```

3. Testing Suricata
    

First, we check if there are logs from Suricata, then we attempt to DDoS the NMS server to view the logs.

```abap
tail -f /var/log/suricata/fast.log
```

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXfv9O0trEaVpJV-tkLWPD2xNg9-YrtjBQQhrTVjWOswmkzSKHDo4FlebCEYPR8AbwbSYgg2dJsAiwsTEwwZjWr2qV8qAf2Og2fzLjf9TKi3gyBSUAFGBf0QZleIhfHjnnRRshmlFIvdXm0xMgodGF8FesE?key=TAh-k7LROlAl0b85eOhptg align="left")

```abap
head -n20 /var/log/suricata/eve.json
```

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXcMcbtLus2a1wgXzWwpfgVuWgYOXftFIunbs-oBzIR0zuDcvQ0NurSj5TZVMyyJysIUK9yNWaUAJNUgZiIFv9oRs7mYmBCWQfRFrmZWTLeMo6dsB0FYERg1uyllZuDDB76a52Y0OplTtlKGUOe-2aTEj5hW?key=TAh-k7LROlAl0b85eOhptg align="left")

Let's test how the logs appear when attacked by a DDoS by accessing our Kali Linux used for the DoS on the NMS server.

```abap
hping3 -S -d 100 –flood -p 80 172.23.1.51
```

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXeaueKoPmr2luSlt3CqX7rW10Tp-lfHVBqFnU2YoNRFOqNpVqFtrJ2DIESVi_VDISRjjN5Qqf-Z2Dou2hO7_ZPJfQTPc_kx1wls9MoPNG0V6B8vWDI-gn2z-RZe541nJ1B4Dyb7RBcF4zGyBlAcjdb8FTk?key=TAh-k7LROlAl0b85eOhptg align="left")

then we check our NMS server with **tail -f /var/log/suricata/fast.log**, and also see if our server's CPU usage increases; if it does, then the DoS is successful and the message displayed by Suricata is also successful.

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXcOjpzH75kdGRSmYoF47jqmrGc7b8e5VHWQbd7cvAKQdwVIhMZ2q42-LT_ehK_ZlD_RmuBUNmJBe7H6qnFSP5LlJn_ehXGEyPWqmHg4sUlf38-PSyTAS36VO8wbZese9mWYFIyB-GUqagqVuaWKbBen01_7?key=TAh-k7LROlAl0b85eOhptg align="left")

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXdN5drTO3KLV_-_TSL4FhZdy1H5ughi_tzsBgOSt6U7XP8gn5bpM6gubYDWCUoXyp9knxCKhFpnBZU3cNT5N21-I2lDiX-ykW9xzXSa4hIClTbhfODqbwIw7gRHwrjKRbdU5R7DOxLUQeL0YWuRO-9SUmA?key=TAh-k7LROlAl0b85eOhptg align="left")

we can see that our CPU experiences a high spike due to the DoS, which means the Suricata logs are correct.

### **Installation and Initial Configuration of Elasticsearch**

1. **Install Elasticsearch**
    
    ```apache
    wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo gpg --dearmor -o /usr/share/keyrings/elasticsearch-keyring.gpg
    apt-get install apt-transport-https
    echo "deb [signed-by=/usr/share/keyrings/elasticsearch-keyring.gpg] https://artifacts.elastic.co/packages/8.x/apt stable main" | tee /etc/apt/sources.list.d/elastic-8.x.list
    apt-get update && sudo apt-get install elasticsearch
    ```
    
    ![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXfoAsLts7Y-OZ9NkiCfkhnrrH2NkGfhVoc1SLdskYHGpv0sBIedsMyh0jptv2OCD6y0j-gDxGyEbI9VF94S0LHbW8fbMuW3Mn67e-AkA_VQk_WjjEmTNOukWG8zAt0wU9ZVdMmEfYYCcns0iGHQXHnWnImg?key=TAh-k7LROlAl0b85eOhptg align="left")
    
    During the installation process, there will be information like this, copy the elastic password and save it in Word/Notepad for later use when connecting to Kibana.
    
2. **Elasticsearch Configuration**
    

After installing, before starting, we first configure it in elasticsearch.yml

```abap
vim /etc/elasticsearch/elasticsearch.yml
```

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXedgUSAsx6BVVwFWlKKGkmE12TW4Tp-5ggJQ7AO4Gf4-MC5XTQbo6CG_7HLXxZiRJosflzP620HRegHcdiL0UDq0jSaq8N3kHHUlO4mJZgGbffXKCAN22tos2ybRzHoRT0jDgHseXrXqo0PQIlCoKaZEGav?key=TAh-k7LROlAl0b85eOhptg align="left")

* * [cluster.name](http://cluster.name)\= whatever
        
    * [node.name](http://node.name)\=use hostname
        
    * [network.host](http://network.host)\= can use server IP or 0.0.0.0
        
    * for http.port=use the default port
        

```abap
ufw allow 9200/tcp
systemctl daemon-reload
systemctl enable elasticsearch.service --now
systemctl status elasticsearch
```

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXcPDrr34mkvWhJtnDN4DmTLeIZ6vD2mL_NbdEaAgesa9ewNt4XqVt7i_0TYgVl25xyIIQB8s5h_v9Cf-I7vBimlGoNWhSUFcx55LU3qIqMcElcGp5R6tiI9gbqTj8QYSPYTyLIuWM06ufWux_Rf2PFFw5JM?key=TAh-k7LROlAl0b85eOhptg align="left")

Now, for Elasticsearch, we're done. Next, let's install Kibana.

3. **Testing Elasticsearch**
    

If the installation and configuration process is complete, let's check if Elasticsearch is running. Open a browser and go to https://ip\_server:9200

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXduKRKGK7567IUhD4gZDx4T4o8ILpHzDdmm7xRS71FZaIClSBOmbfIQuCZqbK6dCnSs4l1sMysNXFhrywADzIqABEjrKNgoqwBOeB-cnYE4aZWZI2E88PbFZJ4RUDrXT1aimpBhuWs1TZMpgfkfQjW85mSZ?key=TAh-k7LROlAl0b85eOhptg align="left")

### **Installation and Configuration of Kibana**

1. **Installation of Kibana**
    

for Kibana installation, it's different from before. Since we've already added the repo and key, we can just install it directly.

```abap
apt install kibana
```

2. **kibana configuration**
    

A fresh installation of Kibana cannot be accessed in the browser yet. We need to configure it with Elasticsearch first to access the Kibana dashboard.

```abap
vim /etc/kibana/kibana.yml
```

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXcXDHQKKdMSWbn6p6z7Et4MWrqKUhZ_uz3qUOwJgE2iFNAvtRsxJ0f96SpFSbGF-UGCHZpjOyyH-Ga3rzu4OUBpwbNnlMPi-nvNcDc8KCKyS1jxBPW1F8JMlMMi9BApKB0hhK-Rcxm-Sr8O4EXOWvyHFiU?key=TAh-k7LROlAl0b85eOhptg align="center")

* server.port= use the default Kibana port
    
* server.host= can use 0.0.0.0/server IP
    

```abap
ufw allow 5061/tcp
systemctl restart kibana
systemctl status kibana
```

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXcbHoMdXuT4czsbwOo4olniYAIqwG8owZye0KHumX1sYSXKnHzCpJPQiWBvgoUETLj4bOtulFSBD1LUUMtBgeNRQJXsY1aVcb70pX-RoRhpTYeaP2THINtfpZfTGeAG2SSE7bpNwAMdYViYSO4wmutqH1G7?key=TAh-k7LROlAl0b85eOhptg align="left")

Now, there is information in the **Go to** [**http://172.23.1.51**](http://172.23.1.51). Open the browser and click the link in the Kibana status.

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXfqngDaVYxRKUGSiSb7dS0JIihWTZNkLXWQUjlF-JNkW3mGauTRgID-obzLZ63CbHndG4hdUkVXPz0sr5jFeGtTIDsnW9529yij0AUoXVRRA4Ow8QtTGhCnYl_udTsiT6yw_lm85gfKXDLK3USoPaWOjVg?key=TAh-k7LROlAl0b85eOhptg align="left")

3. **Connect Kibana with Elasticsearch**
    

Before we can access the Kibana dashboard, we need to connect our Kibana with Elasticsearch. There are several steps, such as creating enrollment and verifying the code.

```abap
/usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token --scope kibana
```

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXcS0V5sX0wxqXxZaTFrNsDTl0u3q6i36KjDDLqgwXC4dWnVp2AvpkL9OXhT26hHxBGgz4YAqZU_sn26IjS7gHpu8riUutZXuMCqMcRg66H8ApiFcRN0Zx8aCeGifF07G2A1WLj3b2CpZatEaDfbyufiqXQ?key=TAh-k7LROlAl0b85eOhptg align="left")

pastekan token yang kita buat di elasticsearch ke enrollment token kibana, jika sudah klik **Configure Elastic**

```abap
open the server and type
/usr/share/kibana/bin/kibana-verification-code
```

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXeUNa7uuZbfqMERnro3BiSVmEPBNuYl2TavqnNRUFihz3orDzvPnXg44QjhVNiIQjj9uqpzQ0Tv042HITLRCRx1H-1OwiBRIPvB4QwW5mywgia488mKv7kXxy-M-PVa7D_t6avFnkgOgdPQQ4NrFN2V3gBW?key=TAh-k7LROlAl0b85eOhptg align="left")

Copy and paste the verification code into the Kibana verification field, then click **Verify**.

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXdBjwMXhCsVGSdK_BNt5wYPOrRn0EIr08jI7shezrm-1xF8H8KQS9adjfWsJpaeUyEsQuM-c1SbCU2wjJ5vmYHddpnIiDbIW5tInZnu3TbKG4HIp9Rf83hqQ9fPBGE5Lu_I3uhSUbdO3_FR2Vx6UcCmqI4?key=TAh-k7LROlAl0b85eOhptg align="left")

* username= elasic
    
* password= password that appears when we first install Elasticsearch.
    

if you forget the password, you can create a new password with command: **/usr/share/elasticsearch/bin/elasticsearch-reset-password -u elastic**

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXdWV8h6tEr1rYO84p9P8tzSOjuNUTlDj0Ls3D-B69O0as7zN_sD5lB3WyFfX-hXPCNQGBvvWw6IUKuZPelME9DcW-ekCisw2-eyr9dEpQeY6gK_FrHAMt6P-WKrahEO5jYHzjc-BC3-xy0DPO5a--SFTQI?key=TAh-k7LROlAl0b85eOhptg align="left")

This is the Kibana dashboard view, but there are no logs yet because we haven't configured our Filebeat with Suricata.

### **Installation and Configuration of Filebeat**

1. **Install Filebeat**
    

We need Filebeat to pull metrics from Suricata to Elasticsearch because Suricata cannot send metrics directly. So, Filebeat acts as an agent. Below are the steps to install Filebeat and configure it to pull Suricata metrics.

```abap
curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-8.14.3-amd64.deb
dpkg -i filebeat-8.14.3-amd64.deb
```

2. **Filebeat Configuration**
    

Now, to allow Filebeat to pull metrics from Suricata to Elasticsearch, we need to configure it first in Filebeat. The configuration is in **filebeat.yml**.

```abap
vim /etc/filebeat/filebeat.yml
```

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXf-LMs0UbmqyKD13A0qM6B0nKfhls__lSSj2o9cmTLSR09MPPgBdDoH7uPI9wGY4odT4H1ObN6n-H8LbAWtaIS6XAXjZoVAiiPg8DQXcQC5PJ3SuHgL9IvRcqGeztZ7RTtmShpZ2cwFwl39CpgTjBlGEQDk?key=TAh-k7LROlAl0b85eOhptg align="left")

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXdBkKuB3AYef1LK_EfGV-0SlJq9FFcPVRuOTaA09ebyzAwPORDa4QZbJkFNBznisUL8KDzXZxvmfChCJE7QUxPj45b6TNShK4RnGU2z7SCyGkX5vPpDLppsdKliQxQqtTHO7L_WvT1Kcg1dz-JHoi6nfvxk?key=TAh-k7LROlAl0b85eOhptg align="left")

There are 2 things we need to configure in filebeat.yml, which are for Elasticsearch and Kibana:

* host elastic = point to the Elastic website
    
* protocol = match our protocol, either http or https
    
* credential = enter the credentials from Elastic that we use to log in
    
* ssl = point ssl to http\_ca.crt located in /etc/elasticsearch/cert
    

And for Kibana, we only need to configure the host.

3. **Connect Filebeat to Suricata**
    

```abap
filebeat modules enable suricata
vim /etc/filebeat/modules.d/suricata.yml
```

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXfC-nmtDEp0fyUmLfd1vfh_XsL_e2bCLVrxaxrneQ82RqgczupMvTuwKEvBQTZbeZZE1CdBKQuw1rO9U3SPTuIk4b6H3J9PUl4_u91rfRH77CkaP4FzUaPYEl8ciSIHXqdUutt4NPC9zIXJLENVzFI9YlI?key=TAh-k7LROlAl0b85eOhptg align="left")

var.path= point to the JSON and log files in Suricata

```abap
filebeat setup
systemctl daemon-reload
systemctl enable --now filebeat
systemctl status filebeat
```

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXeCDijipwdsLmMx0fXExbOKAE2G9jZbFO-m4aJcDZ60HJi2L8SUAO0VbhDW8XbZ0_MztzbcHszFoGrRnTFnkl7SZsyEoN0OKW0kZkuM3-kQF_wgTETlER4yRVrI43jrVDjAzVmygjf_CkpUvsz9831a1NpP?key=TAh-k7LROlAl0b85eOhptg align="left")

Now, we can see that the status is running. Let's try opening it in the Kibana dashboard.

4. **Testing Network Monitoring System**
    

Now let's see if the Suricata logs pulled by Filebeat to Elastic have appeared in Kibana. Open the browser at http://ip\_server:5061

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXcc-VsdGmH1Tqo8GWAXw0asPFwmsS8DSQZDrZgdyRdPz4AOrdXBq4jUUjFLW2b3sKelwqjMHPcN8Nc1CnX289vo0dM3KG4pWGKuAD5SJO5ivGwmv4hhQGAXNrM0ei2vzAotx9mvhV4N3XWMCqxHOXCn5vE?key=TAh-k7LROlAl0b85eOhptg align="left")

Klik **Analytics&gt;Dashboard&gt;\[Filebeat Suricata\] Alert Overview**

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXfdstk683JmL_JXpIEe86iLCFxE6R5cSamFudrmPoJQrI0i3_U4axrhzWw6-SMEaBtulGfB-2VSq6Cj7DdGhJkXSoDZDzN3B5DDuVjSljrUy2_nnTR0de_9MhM4Ro5muQvRNTPzBoMO5JinUC1FxcZqlC4?key=TAh-k7LROlAl0b85eOhptg align="left")

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXdQTJN9sEKMs6bz7Bd7p4tzyt_hix0529Yh7MM7h9rQ0RQDCu81vDxOcpaita6lUw5FALxBTkNMBDyRGxK2HLNbdMYJX7Yi6N8udWGNISv2pC6crYmXy1YWwB7Dje4KCNQiJzWrLA90aqFMIqf8ucEglmkd?key=TAh-k7LROlAl0b85eOhptg align="left")

We can see that the logs pulled by Filebeat have been successfully sent to Elasticsearch. We can also clearly see the logs from Suricata here, and they are easy to understand.

### **Configuration of Netflow and Connect Mikrotik with NMS Server**

This time, let's try monitoring our Mikrotik traffic. Let's see if Kibana can display the current traffic and if we can see any traffic activity. We will use Netflow Filebeat to do this, and of course, we need to connect our Mikrotik with the NMS server.

1. **Netflow Configuration**
    

Before we connect Mikrotik with the NMS server, we need to set up our Netflow in Filebeat located at **/etc/filebeat/modules.d/netflow.yml**.

```abap
cd /etc/filebeat/modules.d
filebeat modules enable netflow
```

2. **Connect Mikrotik ke Server NMS**
    

Open Mikrotik and set up the traffic flow to our NMS server.

`IP>Traffic Flow`

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXfK6swsBHpf3yuj_3cnBhLKXbn6PEN1K4hj8S1zRRwvGviSAVNvoijVZbOPz6UnRTJp9S6tz37xwlIbqqSFyVr11GZ6g_D3Pm7z63HoidT3gT7B22-DByRyuzpFaUVQ0F9beM9esQCLELBXbo-swyZWWp8s?key=TAh-k7LROlAl0b85eOhptg align="left")

click enabled and direct it to all interfaces, then click **Apply &gt; Targets &gt; Add New**

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXc9SV65C2x4z0JPS7pxU9B2kuoO3qnfn5yBkbqhWa1QCrUSaiKDYzdRATZjlZUE5gDzFU8Zl-WFS5N-AB3C_-b9TFZg_OHydCayRyguO7_Vjp2ife6VnMDetM0IR92ALtiui8PglLNu22_XkuQaHrIiYShb?key=TAh-k7LROlAl0b85eOhptg align="left")

* Enabled= check
    
* Dst. Address= direct to the NMS server
    
* port= set the port to 2055, which we configured earlier in netflow
    
* Version= use version IPFIX
    

Once done, click **Apply &gt; Ok**

Once connected, let's check if our netflow can pull traffic from the Mikrotik. Open the Kibana dashboard and click **Analytics&gt;Dashboard&gt;\[Filebeat Netflow\] Traffic Analysis**.

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXcIeoBWhpR5nzTejEclDRtc_YiWakMMyAEdMcrh0wbg3ImDpDSULmSTo4cq2eCcTfwDDs8KffOLJuQD00o64Mrrx9I4DBNsbGFxhRt6QLiWNVtoptXt6cNFv8PY30aB5p6pxUF7Sx-QJ94GO7BpoDwoku60?key=TAh-k7LROlAl0b85eOhptg align="left")

Well, our Filebeat Netflow has successfully pulled traffic from Mikrotik to the Kibana Dashboard.

3. **Testing Netflow Traffic**
    

Once connected, let's check if our Netflow can see heavy traffic and identify which specific IP is causing it. We'll try to DoS the Mikrotik using Kali Linux to test it.

**#Kali Linux**

```abap
hping3 -S -d 10000 --flood -p 80 172.23.1.244
```

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXerISj88fnkBlLvWE-b84YOGY60eu87kvsGp4m9p2Y51zqtvEHUQ0k9yMYoTeD0LWKuu9TSfVS8yYoF-XPQ_UAZbeHw700W61ZhytMEnHS68oM-eFx8imIugZTiFKgMdRVwBqF9g5FB3EOogMA9t91Uk_Y?key=TAh-k7LROlAl0b85eOhptg align="left")

let's check our Kali Linux IP, then run our DoS script on the Mikrotik and see if the Kibana Dashboard can identify the IP causing the heavy traffic.

**#Server NMS**

Open our Kibana dashboard, click **Analytics &gt; Dashboard &gt; \[Filebeat Netflow\] Top-N Flows**, and then scroll down.

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXc8zBI8gm1dxQr6SDIq7hlT6xX8MJJmKBaMMzP-p9P8Zm_EUwBZGbAL7azhQIGVTpCm3XsnKiPyFty0b_7W_muQwaUTFbdUPLc3_WAGiCSsrl3dNUpz18K0IN5J76DiETeIbnKnI-LoyHZ3ndZ-Hyd0UkgS?key=TAh-k7LROlAl0b85eOhptg align="left")

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXfBBBEnzJOd3HFZFM7AjWHNCLal0z-60_GsgQZHDO_TcyF-Bh8jy5oeMDK3NKdG9Zi7ZSjhM3a5G2Kjd0UMXBZRNJ8RuBaE0t4dp1jkRB4A7jMJ2FXVkxFxhe5aAMVVx04w8mohl-0cQckCTcKoBM2RJ17g?key=TAh-k7LROlAl0b85eOhptg align="left")

And yes, our Filebeat Netflow can show us which IP is causing the heavy traffic, and we can also see how many packets are being sent by our Kali Linux.

### **Alerting Suricata to Telegram Bot**

After we create a monitoring dashboard and successfully monitor our server and network, what's next? Well, next we set up alerting so that when an anomaly appears, it will be immediately detected and send a warning to our account.

1. **Create Bot\_Telegram**
    

open Bot Father in Telegram to create a new bot

`Bot Father>New Bot>Name Bot>Username Bot`

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXfeG3zSOBR-vQJoHsLgwr_oqwN_-ql7r4x61C5f5yft6a-fJtn5qtX9Oq9sFbch6EefdtzRAxg9Rh2WlLFacimI6VRKtvHRXjTWoHtgeZEdEIGw4PVmrMcdNPR8tIcF9VWJbqBSf9aPU3EI5CkDIFchSR3W?key=TAh-k7LROlAl0b85eOhptg align="left")

open our bot by searching **bot\_name&gt;/start**

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXd69_KrCMIqT776vWjgAGENonYNEM0zzUz6XmdJF3ytB2bsDM0vGqdMOQ1Byb0o0y0cgNSLQPfW33d9N29BugCpUsHEMVSzxSQNhB7dec1sNsd_0mHOLhefUQxkdh9dD5RHsKvqLfo5wyJJckpL9tae0kV9?key=TAh-k7LROlAl0b85eOhptg align="left")

Salin HTTP Api dan simpan karena akan digunakan untuk konfigurasi di server kita, jika sudah kita lihat ID telegram kita, bisa search **userinfobot&gt;/start**

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXeSxquecKXTWWjZpARTwANXyKO0ojB77tkM1C_2yNGgIgV1oSPI99PjX0HaZbiZIxFP4ajnD2zq-PaWXOjxBv3CRe7XfUK5ptHKpGBfmuVSJREBecuKu0VoD_NAu8NHmfadsmmJ95D-In3na9_Jg-qYX3Rp?key=TAh-k7LROlAl0b85eOhptg align="left")

Now, in this part, we copy our ID and save it because it will be used for configuration on the server.

2. **Install and Configure suricata-telegram-notifier**
    

```abap
git clone https://github.com/infokek/suricata-telegram-notifier
mv suricata-telegram-notifier/configs/service.ini.example
vim suricata-telegram-notifier/configs/service.ini
```

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXconbfeIW3WCsrApz4CZGVbY84_6Ws7JRwaEn1106USNn17bNnkRiNT9xCKo3reSCRjX9lxTooDV7ANir3KWUV6KXOwD5Kv00u5JSWMQOdIdkEHWVv2aSS42wRXDuGF4saMneAumDku2xhbU2nU3JFhEgP8?key=TAh-k7LROlAl0b85eOhptg align="left")

* Bot\_token= use the HTTP API we copied earlier when creating the bot in bot\_father
    
* Chat\_ID= use our Telegram ID that we copied earlier in the bot userinfobot
    
* Interfaces= use the server interface
    

We can see our interface with the command **ip a**

```abap
rm suricata.yml
cp /etc/suricata/suricata.yml 
cd ~/suricata-telegram-notifier/
./install
```

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXdDHTJtUfCI1Gn5bJcR6CUWcDonaHxv56FuMUKgTW_AkWxeARXJLK8sArqs1Drp03EprK_zAz0Hb1Mrrq4AJO2qGkC0C4h_EvNiCFGNXEWFOykimKoqjENqcHrNwzUvK8H4j0K3q1My3yhUl-GgF7WFURKd?key=TAh-k7LROlAl0b85eOhptg align="left")

3. **Testing Alert**
    

We will test our alert to see if it sends a notification when there is an anomaly. We will use the **BruteForce** attack method on our NMS SSH server because I'm tired of only using DoS. Okay, let's open our Kali Linux to start the attack.

```abap
hydra -l root -P rockyou.txt 172.23.1.51 ssh
```

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXdtREIA-Imd6zLW2IXnzrS0yxxhWyhKMVY4aB24g8zFSXs6YMfYBdnvu2bOmazUmNJ4owDFUGf3p1fg8g8KV5sYpmiTblnvkcNknEqx1QCRy49qp-Rze7xVXX5M2Nn6X9wfI9Fl1JOtTcA1LqRDP6DjJyne?key=TAh-k7LROlAl0b85eOhptg align="left")

Well, our brute force attack has been started. Next, let's check our alert bot to see if it sends a notification.

![](https://lh7-rt.googleusercontent.com/docsz/AD_4nXd1dMCadM8ZAPsMvXrNsbM7TKv1xN7jvUKv7HZcZDySEGZF7t6LTue6hQOaS4I-pNd3eJ9xrWd1Hq-djztI2YMDy9-sWXUikVEaztCpYiGzH4JpQ1C5J8gGauCFyVa522f06sN81BHtUinoMuggW5trAqgn?key=TAh-k7LROlAl0b85eOhptg align="left")

and yes, the alert we created was successful

### **Conclusion**

Network Management System (NMS) is an essential tool for monitoring, managing, and securing computer networks. NMS enhances security, performance, and reduces network downtime through proactive threat detection, log analysis, and real-time performance monitoring.

This article explains the installation and configuration of NMS using Suricata for threat detection, ELK Stack (Elasticsearch, Logstash, Kibana) for data collection and analysis, and Filebeat as a log shipping agent. Practical steps include software installation, system configuration, testing, and integration to effectively monitor and manage networks.

With a configured NMS, administrators can monitor traffic, detect attacks, and take quick action through automatic notifications, including integration with Telegram bots for alerting. This system enables early problem detection and faster response to security incidents.

**Important to remember:** Cybersecurity is an ever-evolving process. Therefore, it's crucial to regularly update tools, configurations, and knowledge about the latest threats.
