To visualize Windows Event Logs I've setup an ELK server running all 3 components on the same box. Think for testing and learning ELK should be doable.
Logs forwarded are account lockouts (Event ID 4740) from Domain Controllers.
I was able to pull in and visualize some of these forwarded logs but all of a sudden it stoped. I also noticed the Logstash service restarted automatically on a short but regular interval.
Re-installing the Logstash service fixed this and it is now in a permanent running state. But not log information appears to be shipped.
Looking at the winlogbeat log files the error from the subject of this request for help is shown:
ERR Failed to publish events caused by: read tcp 127.0.0.1:50248->127.0.0.1:5601: i/o timeout
When I enable the debug option for winlogbeat is see the forwarded events it is picking up from the Forwarded Events log on the same server.
Any help or ideas are welcome to solve the error shown
I already read many posts here but none appear to fix my issue.
Platform is Windows Server 2016, 8GB RAM, 2 CPU's
Latest ELK downloads.
Telnet to port 5601 is fine, although slow in response.
Java Platform SE binary takes all the CPU.