Clayton Dukes, CEO
LogZilla is a Centralized Log Management (CLM) platform, designed for IT Operations, Security, and Risk Management leaders who want to gain better incident investigation capabilities by capturing all network and security related logs into a single log collection platform without sacrificing speed or budget.
LogZilla is free for anything under 1M Events per day, so an eve-ng lab should come in well under that :)
The EVE-NG PRO platform is the first clientless multivendor network emulation software that empowers network and security professionals with huge opportunities in the networking world, ready for today’s IT-world requirements. It allows enterprises, e-learning providers/centers, individuals and group collaborators to create virtual proof of concepts, solutions and training environments.
LogZilla Template for EVE-NG
Step 1: Download
Step 2: Add LogZilla files to EVE-NG
tar xzvf eve-logzilla.tgz
cp -rp addons/qemu/logzilla-ubuntu-20.04-server /opt/unetlab/addons/qemu/logzilla-ubuntu-20.04-server
htmlto your unetlab directory:
cp -rp html/ /opt/unetlab/html
- name: LogZilla listname: 'LogZilla Centralized Log Management Platform'
There’s an example of the final file located at
opt/unetlab/html/includes/custom_templates.yml, but if you have customized your
/opt/unetlab/html/includes/custom_templates.yml, don’t just copy this one over it!
Lastly, be sure to fix your unetlab permissions:
/opt/unetlab/wrappers/unl_wrapper -a fixpermissions
Step 3: Adding a LogZilla Node
In the eve-ng GUI, add a new node:
The next menu should show LogZilla assuming you did Step 1 properly:
Leave the defaults as they are. LogZilla requires 8 CPU and 8GB ram to run.
NOTE: You can run it with less, but you would have to manually pull down the kickstart script from https://logzilla.sh and edit it
Connect the newly created node to your internet access:
After the icon turns orange, click it to connect to the console:
You should now have a console similar to:
_ _______ _ _ | | |___ (_) | | | | ___ __ _ / / _| | | __ _ | | / _ / _` | / / | | | |/ _` | | |___| (_) | (_| |/ /__| | | | (_| | |_________/ __, /_____|_|_|_|__,_| __/ | |___/ Ubuntu 20.04.1 LTS eve-logzilla ttyS0 Welcome to LogZilla! Please log in below using the username/password of lzadmin/lzadmin eve-logzilla login:
lzadmin with a password of
Assuming you have internet access, LogZilla will automatically install.
P.S. I’ve included a small helper script in
bin/eve that I use to fix permissions and check IoL images - mostly because I can’t remember the commands :)
It’s optional, but feel free to use it.
chmod 755 bin/eve and run it without parameters to get help.