I just ran filebeat via docker run using the .yml earlier. The dashboards were created but theres no data. When checking index patterns, there's indices. Is my var.path wrong?
For Debian systems the logins will be stored in /var/log/auth.log
For Redhat Systems I think the file is /var/log/secure.
The auth logs vary. Whether the /data/auth.log is having data?
Does any other logs are available in ES from filebeat?
ES requires two plugin installation for the proper working of Filebeat.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.