# DHCP Logs to Logstash

**URL:** <https://discuss.elastic.co/t/dhcp-logs-to-logstash/250777>\
**Category:** Logstash\
**Created:** [October 2, 2020, 10:59am UTC](https://discuss.elastic.co/t/dhcp-logs-to-logstash/250777 "2020-10-02T10:59:18Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Craig2188](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Post date:** [October 2, 2020, 10:59am UTC](https://discuss.elastic.co/t/dhcp-logs-to-logstash/250777/1 "2020-10-02T10:59:18Z")

</div>

I plan to use Filebeat to send the DHCP log file to Logstash.  
I have the following setup in Logstash to send the file to Elasticsearch:

```auto
# Beats -> Logstash -> Elasticsearch pipeline.

input {
  beats {
    port => 5044
  }
}

output {
  elasticsearch {
    hosts => "10.103.186.210:9200"
    manage_template => false
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
  }
}

```

What else do I need to do to have that show up in Kibana correctly? I have looked at the following and used the code stated, but when I do, the services all crash so something is not working correctly, I am assuming it may be due to the version changes maybe and this link being from nearly 2 years ago:

> **[Adding Windows DHCP logs to Elastic - part 1 - Security Distractions](https://www.securitydistractions.com/2019/01/02/adding-windows-dhcp-logs-to-elastic-part-1/)**
>
> How to add Windows DCHP Server logs to Elastic. Gives examples of filebeat and logstash configuration files.

---

<div class="post-metadata">

**Author:** ![kavierkoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavierkoo/32/86555_2.png) [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)\
**Post date:** [October 2, 2020, 11:14am UTC](https://discuss.elastic.co/t/dhcp-logs-to-logstash/250777/2 "2020-10-02T11:14:09Z")

</div>

> [@Craig2188](#):
>
> the services all crash so something is not working correctly

Please share the logs to help with debugging.

---

<div class="post-metadata">

**Author:** ![Craig2188](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Post date:** [October 6, 2020, 8:17am UTC](https://discuss.elastic.co/t/dhcp-logs-to-logstash/250777/3 "2020-10-06T08:17:32Z")

</div>

So for Elasticsearch.yml:

```auto
bootstrap.memory_lock: false
cluster.name: Elastic
http.port: 9200
node.data: true
node.ingest: true
node.master: true
node.max_local_storage_nodes: 1
node.name: SV-MSE-ELTC-001
path.data: D:\Elastic\Elastic-7.9.2\Data
path.logs: D:\Elastic\Elastic-7.9.2\Logs
transport.tcp.port: 9300
xpack.license.self_generated.type: basic
xpack.security.enabled: false
network.host: 0.0.0.0
discovery.seed_hosts: []
discovery.type: single-node

{
  "dhcp": {
    "order": 10,
    "index_patterns": [
      "dhcp-*"
    ],
    "settings": {},
    "mappings": {
      "dhcp": {
        "dynamic_templates": [
          {
            "strings_as_keyword": {
              "mapping": {
                "ignore_above": 1024,
                "type": "keyword"
              },
              "match_mapping_type": "string"
            }
          }
        ],
        "properties": {}
      }
    },
    "aliases": {}
  }
}

```

I get the following error:

```auto
[2020-10-06T01:44:00,876][INFO][o.e.x.m.MlDailyMaintenanceService] [SV-MSE-ELTC-001] triggering scheduled [ML] maintenance tasks
[2020-10-06T01:44:00,892][INFO][o.e.x.m.a.TransportDeleteExpiredDataAction] [SV-MSE-ELTC-001] Deleting expired data
[2020-10-06T01:44:00,892][INFO][o.e.x.m.a.TransportDeleteExpiredDataAction] [SV-MSE-ELTC-001] Completed deletion of expired ML data
[2020-10-06T01:44:00,892][INFO][o.e.x.m.MlDailyMaintenanceService] [SV-MSE-ELTC-001] Successfully completed [ML] maintenance tasks
[2020-10-06T02:30:00,889][INFO][o.e.x.s.SnapshotRetentionTask] [SV-MSE-ELTC-001] starting SLM retention snapshot cleanup task
[2020-10-06T02:30:00,889][INFO][o.e.x.s.SnapshotRetentionTask] [SV-MSE-ELTC-001] there are no repositories to fetch, SLM retention snapshot cleanup task complete
[2020-10-06T09:14:16,198][INFO][o.e.n.Node] [SV-MSE-ELTC-001] stopping ...
[2020-10-06T09:14:16,198][INFO][o.e.x.m.p.l.CppLogMessageHandler] [SV-MSE-ELTC-001] [controller/5896] [Main.cc@154] ML controller exiting
[2020-10-06T09:14:16,198][INFO][o.e.x.w.WatcherService] [SV-MSE-ELTC-001] stopping watch service, reason [shutdown initiated]
[2020-10-06T09:14:16,198][INFO][o.e.x.m.p.NativeController] [SV-MSE-ELTC-001] Native controller process has stopped - no new native processes can be started
[2020-10-06T09:14:16,198][INFO][o.e.x.w.WatcherLifeCycleService] [SV-MSE-ELTC-001] watcher has stopped and shutdown
[2020-10-06T09:14:16,712][INFO][o.e.n.Node] [SV-MSE-ELTC-001] stopped
[2020-10-06T09:14:16,712][INFO][o.e.n.Node] [SV-MSE-ELTC-001] closing ...
[2020-10-06T09:14:16,728][INFO][o.e.n.Node] [SV-MSE-ELTC-001] closed

```

The Logstash settings I can not test until the Elastic service doesnt crash

---

<div class="post-metadata">

**Author:** ![kavierkoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavierkoo/32/86555_2.png) [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)\
**Post date:** [October 6, 2020, 9:09am UTC](https://discuss.elastic.co/t/dhcp-logs-to-logstash/250777/4 "2020-10-06T09:09:44Z")

</div>

Sorry I am kinda confused. What service are crashing? filebeat, logstash or elasticsearch?

and is this issue related to ES crashing?

> [@ES service keeps crashing](https://discuss.elastic.co/t/es-service-keeps-crashing/250661):
>
> Hi, Just realised that after I start the service for Elastic it stops running after about 2 minutes. Checked the event logs and see some errors: Application: elasticsearch.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: Elastic.ProcessHosts.Process.StartupException at Elastic.ProcessHosts.Process.ProcessBase.HandleException(System.Exception) at System.Reactive.ObserverBase1[[System.\_\_Canon, mscorlib, Version=[4.0.0.…

---

<div class="post-metadata">

**Author:** ![Craig2188](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Post date:** [October 6, 2020, 9:11am UTC](https://discuss.elastic.co/t/dhcp-logs-to-logstash/250777/5 "2020-10-06T09:11:42Z")

</div>

Hi,  
Sorry for the confusion. So that other post was mine which is resolved. I then started to look at pushing DHCP logs to logstash so updated the yml files and conf files as per the original link I provided. When I add the code into the Elasticsearch.yml file the service for elastic fails to run

---

<div class="post-metadata">

**Author:** ![kavierkoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavierkoo/32/86555_2.png) [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)\
**Post date:** [October 6, 2020, 10:22am UTC](https://discuss.elastic.co/t/dhcp-logs-to-logstash/250777/6 "2020-10-06T10:22:04Z")

</div>

Thanks for the clarification,

> [@Craig2188](#):
>
> ```auto
> {
> "dhcp": {
> "order": 10,
> "index_patterns": [
> "dhcp-*"
> ],
> "settings": {},
> "mappings": {
> "dhcp": {
> "dynamic_templates": [
> {
> "strings_as_keyword": {
> "mapping": {
> "ignore_above": 1024,
> "type": "keyword"
> },
> "match_mapping_type": "string"
> }
> }
> ],
> "properties": {}
> }
> },
> "aliases": {}
> }
> }
> 
> ```

If I understand correctly, you added above codes in `elasticsearch.yml` right?  
If yes, these codes are not meant to be in `elasticsearch.yml`

> In order for Elasticsearch to correctly handle our DHCP data , we need to provide a index template.

Refer to the link you shared, these codes suppose to be in `index template`.  
Which you can create an `index template` from either one of below methods:

- Kibana \> Stack Management \> Data \> [Index Management](https://www.elastic.co/guide/en/kibana/current/managing-indices.html#manage-index-templates)
- Using [elasticsearch API](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-templates.html)

Hope this can help you!

---

<div class="post-metadata">

**Author:** ![Craig2188](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Post date:** [October 7, 2020, 8:31am UTC](https://discuss.elastic.co/t/dhcp-logs-to-logstash/250777/7 "2020-10-07T08:31:22Z")

</div>

Thanks, that helps, although, I'm still fairly new to ES so not really sure where to proceed with this still, where the file is to edit or create, and then how it ties in with logstash and Elastic?

---

<div class="post-metadata">

**Author:** ![kavierkoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavierkoo/32/86555_2.png) [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)\
**Post date:** [October 7, 2020, 9:18am UTC](https://discuss.elastic.co/t/dhcp-logs-to-logstash/250777/8 "2020-10-07T09:18:09Z")

</div>

Is your kibana up and running? the `index template` is located here

> - Kibana \> Stack Management \> Data \> [Index Management](https://www.elastic.co/guide/en/kibana/current/managing-indices.html#manage-index-templates)

Read up the documentation that will help.  
Elastic also provided some [free fundamental training](https://www.elastic.co/training/free#fundamentals-training) perhaps you could watch it to have a better understanding to Elastic Stack.

---

<div class="post-metadata">

**Author:** ![Craig2188](https://avatars.discourse-cdn.com/v4/letter/c/858c86/32.png) [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Post date:** [October 7, 2020, 10:03am UTC](https://discuss.elastic.co/t/dhcp-logs-to-logstash/250777/9 "2020-10-07T10:03:06Z")

</div>

Awesome, think I got that now. One other thing, I am trying to setup the logstash.conf file for this DHCP output and also winlogbeats and filebeats (dhcp), would the output section of logstash.conf file be like this:

```auto
output {
  if [type] == "dhcp"
  {
    elasticsearch {
      hosts => "10.103.186.210:9200"
	  manage_template => false
      index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
      document_type => "%{[@metadata][type]}"
      index => "dchp-%{+YYYY.MM.dd}"
		}
    }
    else if [type] == "log" {
        elasticsearch {
			hosts => "10.103.186.210:9200"
			manage_template => false
			index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
			document_type => "%{[@metadata][type]}"
		}
	}
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2020, 10:03am UTC](https://discuss.elastic.co/t/dhcp-logs-to-logstash/250777/10 "2020-11-04T10:03:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
