Don’t see logs in kibana stack monitoring

Hmmm... Even if I added:


  ssl.certificate: "/etc/kibana/es.crt.pem"

  ssl.key: "/etc/kibana/es.key.pem"

in Kibana section gives tha same error.

I'm curious - can this be an error cause by nginx reverse proxy?

Edit: one step closer to solution - I forgot to change Kibana ip address in 'filebeat.yml' - as I use nginx and KeepAliveD it is necessary to do it.
This is log for filebeat setup -e:

2022-09-02T11:56:39.685+0200	INFO	[esclientleg]	eslegclient/connection.go:285	Attempting to connect to Elasticsearch version 7.17.6
2022-09-02T11:56:40.046+0200	INFO	[modules]	fileset/pipelines.go:133	Elasticsearch pipeline loaded.	{"pipeline": "filebeat-7.17.6-elasticsearch-slowlog-pipeline"}
2022-09-02T11:56:40.358+0200	INFO	[modules]	fileset/pipelines.go:133	Elasticsearch pipeline loaded.	{"pipeline": "filebeat-7.17.6-elasticsearch-slowlog-pipeline-plaintext"}
2022-09-02T11:56:40.629+0200	INFO	[modules]	fileset/pipelines.go:133	Elasticsearch pipeline loaded.	{"pipeline": "filebeat-7.17.6-elasticsearch-slowlog-pipeline-json"}
2022-09-02T11:56:40.880+0200	INFO	[modules]	fileset/pipelines.go:133	Elasticsearch pipeline loaded.	{"pipeline": "filebeat-7.17.6-elasticsearch-audit-pipeline"}
2022-09-02T11:56:41.185+0200	INFO	[modules]	fileset/pipelines.go:133	Elasticsearch pipeline loaded.	{"pipeline": "filebeat-7.17.6-elasticsearch-audit-pipeline-json"}
2022-09-02T11:56:41.516+0200	INFO	[modules]	fileset/pipelines.go:133	Elasticsearch pipeline loaded.	{"pipeline": "filebeat-7.17.6-elasticsearch-audit-pipeline-plaintext"}
2022-09-02T11:56:41.743+0200	INFO	[modules]	fileset/pipelines.go:133	Elasticsearch pipeline loaded.	{"pipeline": "filebeat-7.17.6-elasticsearch-deprecation-pipeline"}
2022-09-02T11:56:41.963+0200	INFO	[modules]	fileset/pipelines.go:133	Elasticsearch pipeline loaded.	{"pipeline": "filebeat-7.17.6-elasticsearch-deprecation-pipeline-plaintext"}
2022-09-02T11:56:42.200+0200	INFO	[modules]	fileset/pipelines.go:133	Elasticsearch pipeline loaded.	{"pipeline": "filebeat-7.17.6-elasticsearch-deprecation-pipeline-json"}
2022-09-02T11:56:42.503+0200	INFO	[modules]	fileset/pipelines.go:133	Elasticsearch pipeline loaded.	{"pipeline": "filebeat-7.17.6-elasticsearch-gc-pipeline"}
2022-09-02T11:56:42.739+0200	INFO	[modules]	fileset/pipelines.go:133	Elasticsearch pipeline loaded.	{"pipeline": "filebeat-7.17.6-elasticsearch-server-pipeline"}
2022-09-02T11:56:43.038+0200	INFO	[modules]	fileset/pipelines.go:133	Elasticsearch pipeline loaded.	{"pipeline": "filebeat-7.17.6-elasticsearch-server-pipeline-plaintext"}
2022-09-02T11:56:43.315+0200	INFO	[modules]	fileset/pipelines.go:133	Elasticsearch pipeline loaded.	{"pipeline": "filebeat-7.17.6-elasticsearch-server-pipeline-json"}
2022-09-02T11:56:43.320+0200	INFO	[esclientleg]	eslegclient/connection.go:105	elasticsearch url: https://{{ip_address}}:{{port_number}}
2022-09-02T11:56:43.320+0200	WARN	[tls]	tlscommon/tls_config.go:101	SSL/TLS verifications disabled.
2022-09-02T11:56:43.320+0200	INFO	[esclientleg]	eslegclient/connection.go:105	elasticsearch url: https://{{ip_address}}:{{port_number}}
2022-09-02T11:56:43.320+0200	WARN	[tls]	tlscommon/tls_config.go:101	SSL/TLS verifications disabled.
2022-09-02T11:56:43.320+0200	INFO	[esclientleg]	eslegclient/connection.go:105	elasticsearch url: https://{{ip_address}}:{{port_number}}
2022-09-02T11:56:43.321+0200	WARN	[tls]	tlscommon/tls_config.go:101	SSL/TLS verifications disabled.
2022-09-02T11:56:43.321+0200	WARN	[tls]	tlscommon/tls_config.go:101	SSL/TLS verifications disabled.
2022-09-02T11:56:43.349+0200	INFO	[esclientleg]	eslegclient/connection.go:285	Attempting to connect to Elasticsearch version 7.17.6
2022-09-02T11:56:43.577+0200	INFO	[modules]	fileset/pipelines.go:133	Elasticsearch pipeline loaded.	{"pipeline": "filebeat-7.17.6-logstash-log-pipeline"}
2022-09-02T11:56:43.897+0200	INFO	[modules]	fileset/pipelines.go:133	Elasticsearch pipeline loaded.	{"pipeline": "filebeat-7.17.6-logstash-log-pipeline-plaintext"}
2022-09-02T11:56:44.164+0200	INFO	[modules]	fileset/pipelines.go:133	Elasticsearch pipeline loaded.	{"pipeline": "filebeat-7.17.6-logstash-log-pipeline-json"}
2022-09-02T11:56:44.427+0200	INFO	[modules]	fileset/pipelines.go:133	Elasticsearch pipeline loaded.	{"pipeline": "filebeat-7.17.6-logstash-slowlog-pipeline"}
2022-09-02T11:56:44.786+0200	INFO	[modules]	fileset/pipelines.go:133	Elasticsearch pipeline loaded.	{"pipeline": "filebeat-7.17.6-logstash-slowlog-pipeline-plaintext"}
2022-09-02T11:56:45.018+0200	INFO	[modules]	fileset/pipelines.go:133	Elasticsearch pipeline loaded.	{"pipeline": "filebeat-7.17.6-logstash-slowlog-pipeline-json"}
2022-09-02T11:56:45.018+0200	INFO	cfgfile/reload.go:262	Loading of config files completed.
2022-09-02T11:56:45.018+0200	INFO	[load]	cfgfile/list.go:138	Stopping 2 runners ...
Loaded Ingest pipelines

It seems to work. I will test it for 2-3 days.
obraz

1 Like

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.