WhatsApp Group Chat Analysis using ELK

The Elastic Stack is becoming increasingly popular with security analytics with any form of log inputs.¬† In this post, we learn about how ELK can be used for analyze the messages in a WhatsApp group and to generate some interesting visualizations and reports. The “Email chat” feature is used to send the group chat messages to an email with media omitted and the text file containing the chat messages is downloaded from the email and copied to a filebeat installation folder. Once the file is copied the messages from the text file are pushed to the logstash beat sensor.

Logstash beat input

Logstash filter excert

Logstash output configuration

filebeat.yml

Text file in the specified folder

WhatsApp messages in the Kibana console

Top 10 senders during the selected time frame

Rate of messages sent to the group

Top sender’s message count

 

Please follow and like us: