Aaaaand here I am again, continuing my monologue.
I've now moved my settings from modules.d/suricata.yml
and modules.d/system.yml
into filebeat/filebeat.yml
. That allowed me to run the setups for both system
and suricata
without any errors. I also ran the full setup via sudo filebeat setup -e
and got no errors.
However, the Kibana dashboard still shows nothing.
The discover page is also completely empty
I'm absolutely out of ideas and patience.