7.26.0 7.25.0 7.24.0 7.23.0 7.22.0 7.21.0 7.20.0 7.19.0 7.18.0
7.26.0 7.25.0 7.24.0 7.23.0 7.22.0 7.21.0 7.20.0 7.19.0 7.18.0

Using OpenSearch Dashboards with LogRhythm SIEM

For customers looking to leverage additional visualization tools, LogRhythm SIEM version 7.26 and higher is compatible with OpenSearch Dashboards.

Designing OpenSearch Dashboards with LogRhythm

By default, OpenSearch Dashboards connect to the local OpenSearch node running on the host where you install OpenSearch Dashboards, listening on localhost:9200 by default. This connection to the local node allows you to visualize data from all nodes within the same cluster.

In a Windows/XM configuration, you should run one OpenSearch Dashboard UI for each XM in your environment. This could be multiple instances if you have a DR configuration.

For Linux DX configurations, you can run one OpenSearch Dashboard UI for each cluster from which you want to visualize data. You can pick any node in the cluster from which to run OpenSearch Dashboards and it will visualize all data within that cluster. OpenSearch Dashboards can visualize open index data only (hot tier), so any closed indexes (warm tier) will not be visible.

Support for multi-cluster OpenSearch Dashboard configurations is possible, but due to the complexities associated with cross-cluster communication/authentication, this is considered a custom configuration for every deployment. Please refer to our Professional Services team for assistance with this type of configuration. OpenSearch Dashboards offer a configuration for remote Data Sources, which is the recommended configuration method as it avoids cross-cluster search (CCS).

OpenSearch Dashboard Versions

The version of OpenSearch Dashboards must match the version of OpenSearch being used. In the event that your LogRhythm version is upgraded, you may need to upgrade OpenSearch Dashboards.

LogRhythm Version

OpenSearch Version

Download Link

LogRhythm SIEM 7.26.0+

OpenSearch 2.19.5

OpenSearch Dashboards 2.19.5 Download

Warnings and Disclaimers

OpenSearch Dashboards are a third-party software and are licensed under third-party terms. OpenSearch Dashboards are licensed under the Apache 2.0 license agreement and can be used with LogRhythm.

OpenSearch Dashboards may have a detrimental effect on LogRhythm SIEM's indexing and search performance, as this can generate significant additional load against the hosts/clusters. Use of OpenSearch Dashboards is at your own risk and only recommended on SSD/Flash based storage systems without existing disk performance limitations.

LogRhythm cannot provide support for OpenSearch Dashboards, and if OpenSearch Dashboards negatively impact your Data Indexer, LogRhythm may ask you to remove the instance of OpenSearch Dashboards per LogRhythm's Support Services Addendum.

LogRhythm SIEM and OpenSearch Dashboards Configuration

OpenSearch's Security plugin is enabled by default; all traffic (API and UI) requires authentication and uses HTTPS with self-signed certificates issued by an internal LogRhythm CA. The steps below install and configure OpenSearch Dashboards to work with this.

Migrating Existing Kibana Dashboards

If moving from Kibana 7.10.2 (OSS), OpenSearch Dashboards can import its saved-object exports directly. Prior to Upgrading your LogRhythm SIEM to version 7.26, you should export your Kibana Dashboards.

  1. In Kibana, navigate to Stack Management → Saved Objects → Export (select objects or export all) to produce an NDJSON file.

  2. In OpenSearch Dashboards, navigate to Stack Management → Saved Objects → Import, and select that file.

  3. Resolve any conflicts, and re-point unresolved index-pattern references at logs-*.

  4. Test on a non-production instance first; some visualization types changed between the Kibana 7.10.2 line and current OpenSearch Dashboards releases.

Linux DX

  1. Confirm the OpenSearch cluster is healthy:

    sudo /usr/local/logrhythm/tools/dx-curl.sh /_cluster/health?pretty
    
  2. (Offline environments only) Download the matching bundle from a machine with internet access and copy it to /home/logrhythm/Soft/opensearch-dashboards-<version>-linux-x64.tar.gz before running the script:

    https://artifacts.opensearch.org/releases/bundle/opensearch-dashboards/<version>/opensearch-dashboards-<version>-linux-x64.tar.gz
    
  3. Run the script as root:

    sudo OSD_ADMIN_PASSWORD='<your-password>' /usr/local/logrhythm/tools/install-opensearch-dashboards.sh
    

    This will create the kibanaserver and osdadmin OpenSearch accounts, configures and starts the opensearch-dashboards systemd service, and opens firewall ports 5601/tcp and 9200/tcp. This command is safe to re-run.

  4. Browse to https://<dx-node-ip>:5601 and log in as osdadmin with the password you set. Accept the self-signed certificate warning.

  5. Create the index pattern by navigating to Stack Management → Index Patterns → Create index pattern → logs-* → Time field normalDate.

Windows XM / Single-Node DX

  1. Launch Powershell as an Administrator.

  2. Confirm OpenSearch is running with the following command:

    PowerShell
    Get-Service lr-opensearch
    
  3. (Offline environments only) Download the matching bundle from a machine with internet access and copy it to C:\LogRhythm\OpenSearchDashboards\packages\opensearch-dashboards-<version>-windows-x64.zip before running this script:

    https://artifacts.opensearch.org/releases/bundle/opensearch-dashboards/<version>/opensearch-dashboards-<version>-windows-x64.zip
    
  4. From an elevated PowerShell prompt, run:

    PowerShell
    powershell -File "C:\Program Files\LogRhythm\Data Indexer\tools\install-opensearch-dashboards.ps1" -OsdAdminPassword "<your-password>"
    

    This installs OpenSearch Dashboards to C:\LogRhythm\OpenSearchDashboards, generates its TLS certificate, creates the osddashboard and osdadmin OpenSearch accounts, registers the lr-opensearch-dashboards Windows service, and opens firewall port 5601/tcp. OpenSearch's own port 9200 is left loopback-only.

  5. Browse to https://<host-ip>:5601 and log in as osdadmin with the password you set. Accept the self-signed certificate warning.

  6. Create the index pattern by navigating to Stack Management → Index Patterns → Create index pattern → logs-* → Time field normalDate.

Troubleshooting OpenSearch Dashboards

Linux

  1. Service status/logs: sudo systemctl status opensearch-dashboards, sudo journalctl -u opensearch-dashboards -n 100.

  2. Confirm the osdadmin account: sudo /usr/local/logrhythm/tools/dx-curl.sh /_plugins/_security/api/internalusers/osdadmin.

Windows

  1. Service status: Get-Service lr-opensearch-dashboards.

  2. Confirm the osdadmin account: & "C:\Program Files\LogRhythm\Data Indexer\tools\dx-curl.ps1" /_plugins/_security/api/internalusers/osdadmin.

  • Least-privilege user roles. osdadmin has full administrative access. Consider scoped read-only accounts (e.g. built-in kibana_read_only) for analysts.