Filebeat nginx dashboard kubernetes

I am new to ELK and IT field started as a devops recently so you can consider me being a complete noob.

I am having trouble setting up the filebeat nginx dashboard.
deployed the ELK on Kubernetes cluster, using the nginx ingress, I can see the logs coming but it doesn't include the GEOIP in fields, i have used the ingest pipeline as suggested in the link Enrich events with geoIP information | Filebeat Reference [7.17] | Elastic but still it doesn't work .

However It works fine if i use the logstash as the output with filter, then geo.location is detected and i can see the geo.location on map but the dashboard couldn't find the filebeat index and using setup.dashboards.index: "logstash-*" still wont work. it still looks for filebeat index

attaching the configmap for reference

filebeat.yml: |-
    setup.dashboards.enabled: true
      index.number_of_shards: 1
        - type: kubernetes
          node: ${NODE_NAME}
          hints.enabled: true
            - config:
                - type: container
                    - /var/lib/docker/containers/*/${}-json.log
                  exclude_lines: ["^\\s+[\\-`('.|_]"]
                    - drop_event.when.not.or:
                        - equals.kubernetes.namespace: "ingress-nginx"
      - add_cloud_metadata:
      - add_host_metadata:
      - add_docker_metadata:
      - add_kubernetes_metadata:

      hosts: elasticsearch.kube-logging:9200
      pipeline: geoip-info
      #hosts: logstash-service.kube-logging:5044 "kibana-np.kube-logging.svc.cluster.local"
    setup.kibana.protocol: "http"
    setup.dashboards.index: "logstash-*"

any help will be greatly appreciated if someone can help me point out what i am doing wrong.


This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.