I have created an ELK server on Ubuntu 20.04LTS - and would like to monitor both Normal Linux/Windows Server - and allso our PFsense Routers.
I'm using the PFELK --> GitHub - pfelk/pfelk: pfSense/OPNsense + ELK to monitor our PFsense
But its like I cannot have both setups running at the same time! and the questions is why
Is it that both default uses Filebeat as the data collector - and can not make it work
Seperatly If I create an install for normal machines - this work
Allso installing pfelk as single install - is working
But when I using Both at the same time - I'm only getting information from PFsense - not all other PC - there just no data after the PFelk is installed
Than all logs files from other machines are sending to the ELK server
Then I do the Installation for PFsense - using this guide --> GitHub - pfelk/pfelk: pfSense/OPNsense + ELK
Using the Script for installing. no errors or reinstallation of the packages
And then afterwards I'm logging from PFsense - But not from all other machines!
My guess is that PFELK overrules the filebeat setup and therefor only see the PFELK solutions
Asking about config setup - I haven't done anything else other that what the guides describes.
There was data before installing PFelk - in this
After installing PFELK it'll just show the above image - and no data are getting to the ELK server from Servers
a Restart of filebeat gives me this logfile:
It'll shoiw active status when using systemctl
The exact thing that goes wrong - is when I'm using their automatic installation, All indexes setup before runnign the script - and trhen just showing no information are noticed for filebeat index!
But I not sure where this error are created -. Which files would you like to see - since I'm getting lost when I look through the fiules and which configuration are you interested in
I had a look at pfelk/ubuntu.md at main · pfelk/pfelk · GitHub, as the install script is a bit much to pull apart, and it does overwrite things in Logstash and Kibana, so it's likely that is the cause of the issue.
So I cannot see where and why it goes wrong - as I see it, So I cannot figure out where the issue is in this setup - but It should be possible to make this work
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.