For customers looking to leverage additional visualization tools, LogRhythm SIEM version 7.26 and higher is compatible with OpenSearch Dashboards.
Designing OpenSearch Dashboards with LogRhythm
By default, OpenSearch Dashboards connect to the local OpenSearch node running on the host where you install OpenSearch Dashboards, listening on localhost:9200 by default. This connection to the local node allows you to visualize data from all nodes within the same cluster.
In a Windows/XM configuration, you should run one OpenSearch Dashboard UI for each XM in your environment. This could be multiple instances if you have a DR configuration.
For Linux DX configurations, you can run one OpenSearch Dashboard UI for each cluster from which you want to visualize data. You can pick any node in the cluster from which to run OpenSearch Dashboards and it will visualize all data within that cluster. OpenSearch Dashboards can visualize open index data only (hot tier), so any closed indexes (warm tier) will not be visible.
Support for multi-cluster OpenSearch Dashboard configurations is possible, but due to the complexities associated with cross-cluster communication/authentication, this is considered a custom configuration for every deployment. Please refer to our Professional Services team for assistance with this type of configuration. OpenSearch Dashboards offer a configuration for remote Data Sources, which is the recommended configuration method as it avoids cross-cluster search (CCS).
OpenSearch Dashboard Versions
The version of OpenSearch Dashboards must match the version of OpenSearch being used. In the event that your LogRhythm version is upgraded, you may need to upgrade OpenSearch Dashboards.
|
LogRhythm Version |
OpenSearch Version |
Download Link |
|---|---|---|
|
LogRhythm SIEM 7.26.0+ |
OpenSearch 2.19.5 |
Warnings and Disclaimers
OpenSearch Dashboards are a third-party software and are licensed under third-party terms. OpenSearch Dashboards are licensed under the Apache 2.0 license agreement and can be used with LogRhythm.
OpenSearch Dashboards may have a detrimental effect on LogRhythm SIEM's indexing and search performance, as this can generate significant additional load against the hosts/clusters. Use of OpenSearch Dashboards is at your own risk and only recommended on SSD/Flash based storage systems without existing disk performance limitations.
LogRhythm cannot provide support for OpenSearch Dashboards, and if OpenSearch Dashboards negatively impact your Data Indexer, LogRhythm may ask you to remove the instance of OpenSearch Dashboards per LogRhythm's Support Services Addendum.
LogRhythm SIEM and OpenSearch Dashboards Configuration
OpenSearch's Security plugin is enabled by default; all traffic (API and UI) requires authentication and uses HTTPS with self-signed certificates issued by an internal LogRhythm CA. The steps below install and configure OpenSearch Dashboards to work with this.
Migrating Existing Kibana Dashboards
If moving from Kibana 7.10.2 (OSS), OpenSearch Dashboards can import its saved-object exports directly. Prior to Upgrading your LogRhythm SIEM to version 7.26, you should export your Kibana Dashboards.
-
In Kibana, navigate to Stack Management → Saved Objects → Export (select objects or export all) to produce an NDJSON file.
-
In OpenSearch Dashboards, navigate to Stack Management → Saved Objects → Import, and select that file.
-
Resolve any conflicts, and re-point unresolved index-pattern references at
logs-*. -
Test on a non-production instance first; some visualization types changed between the Kibana 7.10.2 line and current OpenSearch Dashboards releases.
Linux DX
-
Confirm the OpenSearch cluster is healthy:
sudo /usr/local/logrhythm/tools/dx-curl.sh /_cluster/health?pretty -
(Offline environments only) Download the matching bundle from a machine with internet access and copy it to
/home/logrhythm/Soft/opensearch-dashboards-<version>-linux-x64.tar.gzbefore running the script:https://artifacts.opensearch.org/releases/bundle/opensearch-dashboards/<version>/opensearch-dashboards-<version>-linux-x64.tar.gz -
Run the script as root:
sudo OSD_ADMIN_PASSWORD='<your-password>' /usr/local/logrhythm/tools/install-opensearch-dashboards.shThis will create the
kibanaserverandosdadminOpenSearch accounts, configures and starts theopensearch-dashboardssystemd service, and opens firewall ports5601/tcpand9200/tcp. This command is safe to re-run. -
Browse to
https://<dx-node-ip>:5601and log in asosdadminwith the password you set. Accept the self-signed certificate warning. -
Create the index pattern by navigating to Stack Management → Index Patterns → Create index pattern →
logs-*→ Time fieldnormalDate.
Windows XM / Single-Node DX
-
Launch Powershell as an Administrator.
-
Confirm OpenSearch is running with the following command:
PowerShellGet-Service lr-opensearch -
(Offline environments only) Download the matching bundle from a machine with internet access and copy it to
C:\LogRhythm\OpenSearchDashboards\packages\opensearch-dashboards-<version>-windows-x64.zipbefore running this script:https://artifacts.opensearch.org/releases/bundle/opensearch-dashboards/<version>/opensearch-dashboards-<version>-windows-x64.zip -
From an elevated PowerShell prompt, run:
PowerShellpowershell -File "C:\Program Files\LogRhythm\Data Indexer\tools\install-opensearch-dashboards.ps1" -OsdAdminPassword "<your-password>"This installs OpenSearch Dashboards to
C:\LogRhythm\OpenSearchDashboards, generates its TLS certificate, creates theosddashboardandosdadminOpenSearch accounts, registers thelr-opensearch-dashboardsWindows service, and opens firewall port5601/tcp. OpenSearch's own port 9200 is left loopback-only. -
Browse to
https://<host-ip>:5601and log in asosdadminwith the password you set. Accept the self-signed certificate warning. -
Create the index pattern by navigating to Stack Management → Index Patterns → Create index pattern →
logs-*→ Time fieldnormalDate.
Troubleshooting OpenSearch Dashboards
Linux
-
Service status/logs:
sudo systemctl status opensearch-dashboards,sudo journalctl -u opensearch-dashboards -n 100. -
Confirm the
osdadminaccount:sudo /usr/local/logrhythm/tools/dx-curl.sh /_plugins/_security/api/internalusers/osdadmin.
Windows
-
Service status:
Get-Service lr-opensearch-dashboards. -
Confirm the
osdadminaccount:& "C:\Program Files\LogRhythm\Data Indexer\tools\dx-curl.ps1" /_plugins/_security/api/internalusers/osdadmin.
Recommended Follow-ups
-
Least-privilege user roles.
osdadminhas full administrative access. Consider scoped read-only accounts (e.g. built-inkibana_read_only) for analysts.