Hi below are my contents in my packetbeat.yml file.
packetbeat.interfaces.device: any
packetbeat.interfaces.type: af_packet
packetbeat.interfaces.buffer_size_mb: 100
packetbeat.flows:
timeout: 30s
period: 10s
packetbeat.protocols:
- type: icmp
enabled: true
- type: amqp
ports: [5672]
- type: cassandra
ports: [9042]
- type: dhcpv4
ports: [67, 68]
- type: dns
ports: [53]
- type: http
ports: [80, 8080, 8000, 5000, 8002]
- type: memcache
ports: [11211]
- type: mysql
ports: [3306,3307]
- type: pgsql
ports: [5432]
- type: redis
ports: [6379]
- type: thrift
ports: [9090]
- type: mongodb
ports: [27017]
- type: nfs
ports: [2049]
- type: tls
ports:
- 443 # HTTPS
- 993 # IMAPS
- 995 # POP3S
- 5223 # XMPP over SSL
- 8443
- 8883 # Secure MQTT
- 9243 # Elasticsearch
setup.template.settings:
index.number_of_shards: 1
index.number_of_replicas: 0
setup.template.name: "packetbeat"
setup.template.pattern: "packetbeat-*"
setup.dashboards.enabled: true
setup.kibana:
host: "ip:5910"
output.elasticsearch:
hosts: ["ip:9200"]
username: ""
password: "**"
index: "%{[fields.log_type]}-%{[agent.version]}-%{+yyyy.MM.dd}"
pipeline: "%{[fields.log_type]}_pipeline"
logging.level: debug
logging.to_files: true
logging.files:
path: /var/log/packetbeat
name: packetbeat
keepfiles: 7
permissions: 0644
xpack.monitoring.enabled: true
xpack.monitoring.elasticsearch:
username: ""
password: "**"
Both Packetbeat and kibana are same version as 7.1.1.
2020-02-19T15:22:54.990+0800 INFO [monitoring] log/log.go:153 Uptime: 15.672521028s
2020-02-19T15:22:54.990+0800 INFO [monitoring] log/log.go:130 Stopping metrics logging.
2020-02-19T15:22:54.990+0800 DEBUG [monitoring] pipeline/client.go:149 client: closing acker
2020-02-19T15:22:54.990+0800 INFO [monitoring] elasticsearch/elasticsearch.go:277 Stop monitoring stats metrics snapshot loop.
2020-02-19T15:22:54.990+0800 DEBUG [monitoring] pipeline/client.go:151 client: done closing acker
2020-02-19T15:22:54.990+0800 INFO [monitoring] elasticsearch/elasticsearch.go:277 Stop monitoring state metrics snapshot loop.
2020-02-19T15:22:54.990+0800 DEBUG [monitoring] pipeline/client.go:155 client: cancelled 0 events
2020-02-19T15:22:54.990+0800 DEBUG [monitoring] pipeline/pipeline.go:242 close pipeline
2020-02-19T15:22:54.990+0800 INFO instance/beat.go:388 packetbeat stopped.
2020-02-19T15:22:54.999+0800 ERROR instance/beat.go:802 Exiting: Error importing Kibana dashboards: fail to import the dashboards in Kibana: Error importing directory /usr/share/packetbeat/kibana: Failed to import dashboard: Failed to load directory /usr/share/packetbeat/kibana/7/dashboard:
error loading /usr/share/packetbeat/kibana/7/dashboard/Packetbeat-cassandra.json: . Response: {"objects":[{"id":"Cassandra-ResponseKeyspace-ecs","type":"visualization","updated_at":"2020-02-19T07:28:43.802Z","version":"WzI4MzQ1MjUsODBd","attributes":{"description":"","kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[],\"query\":{\"que... (truncated)
error loading /usr/share/packetbeat/kibana/7/dashboard/Packetbeat-thrift.json: . Response: {"objects":[{"id":"Navigation-ecs","type":"visualization","updated_at":"2020-02-19T07:28:56.052Z","version":"WzI4MzQ2MzksODBd","attributes":{"description":"","kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[],\"query\":{\"query\":{\"query_st... (truncated)
error loading /usr/share/packetbeat/kibana/7/dashboard/Packetbeat-tls.json: . Response: {"objects":[{"id":"Navigation-ecs","type":"visualization","updated_at":"2020-02-19T07:28:57.170Z","version":"WzI4MzQ2NDgsODBd","attributes":{"description":"","kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[],\"query\":{\"query\":{\"query_st... (truncated)
Exiting: Error importing Kibana dashboards: fail to import the dashboards in Kibana: Error importing directory /usr/share/packetbeat/kibana: Failed to import dashboard: Failed to load directory /usr/share/packetbeat/kibana/7/dashboard:
error loading /usr/share/packetbeat/kibana/7/dashboard/Packetbeat-cassandra.json: . Response: {"objects":[{"id":"Cassandra-ResponseKeyspace-ecs","type":"visualization","updated_at":"2020-02-19T07:28:43.802Z","version":"WzI4MzQ1MjUsODBd","attributes":{"description":"","kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[],\"query\":{\"que... (truncated)
error loading /usr/share/packetbeat/kibana/7/dashboard/Packetbeat-thrift.json: . Response: {"objects":[{"id":"Navigation-ecs","type":"visualization","updated_at":"2020-02-19T07:28:56.052Z","version":"WzI4MzQ2MzksODBd","attributes":{"description":"","kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[],\"query\":{\"query\":{\"query_st... (truncated)
error loading /usr/share/packetbeat/kibana/7/dashboard/Packetbeat-tls.json: . Response: {"objects":[{"id":"Navigation-ecs","type":"visualization","updated_at":"2020-02-19T07:28:57.170Z","version":"WzI4MzQ2NDgsODBd","attributes":{"description":"","kibanaSavedObjectMeta":{"searchSourceJSON":"{\"filter\":[],\"query\":{\"query\":{\"query_st... (truncated)
2020-02-19T15:22:54.990+0800 DEBUG [monitoring] pipeline/consumer.go:190 stop pipeline event consumer
Or is it because my rights issue?
-rw-r--r-- 1 root root 147301 May 23 2019 fields.yml
-rw-r--r-- 1 root root 60984 May 23 2019 packetbeat.reference.yml
-rw------- 1 root root 8836 Feb 20 11:05 packetbeat.yml