Wednesday, November 23, 2016

HOWTO : EveBox on Almond Croissants and Danish

EveBox is a web based Suricata "eve" event viewer for ElasticSearch. ElasticSearch is installed on Almond Croissants or Danish by default. However, EveBox is not installed by default. You need to install it yourself.

Almond Croissants is an Intrusion Detection and Prevention System while Danish is an Intrusion Detection System. Almond Croissants and Danish are created based on Suricata by Samiux under GPL version 3.

In general speaking, EveBox is for advanced Almond Croissants or Danish users.

Step 1a :

sudo cp evebox-0.5.0-linux-amd64/evebox /usr/bin/


Step 1b :

wget -O
sudo cp evebox-0.6.0dev-linux-amd64/evebox /usr/bin/

Step 2 :

sudo nano /lib/systemd/system/evebox.service

Description=EveBox Web Interface

ExecStart=/usr/bin/evebox -e http://localhost:9200


Step 3 :

sudo systemctl enable evebox.service
sudo systemctl start evebox.service

To access it, use your browser to surf :

http://[Almond Croissants IP address]:5636

Update or Upgrade

sudo systemctl stop evebox.service

Repeat Step 1a or 1b.

sudo systemctl start evebox.service

That's all! See you.