I am using ELK 6.4.0 and Beats (Filebeat, Metricbeat) 6.4.0. Currently my architecture is Beat->Logstash->Elasticsearch->Kibana.
I am using Filebeat System module and ouput in filebeat.yml is logstash. In this case, logs are coming on kibana dashboard via system module. But logs are not showing in Filebeat syslog and SSH dashboard.
But when i am replacing output logstash with elasticsearch in filebeat.yml file then logs are coming on kibana dashboard as well as showing on Syslog and SSH filebeat dashboard.
is logstash unable to add those required fileds or something else?
I want to use logstash and Filebeat Syslog and SSH dashboard so that we can easily visualize the SSH loging attempt like success and failed with geolocation.
Please help me to troubleshoot the issue.
I am getting one more error when running the below command on filebeat server:
filebeat -e -modules=nginx -setup -E "output.elasticsearch.hosts=["http://localhost:9200"]"
ERROR registrar/registrar.go:363 Writing of registry returned error: rename /var/lib/filebeat/registry.new /var/lib/filebeat/registry: no such file or directory. Continuing...
I have checked /var/lib/filebeat/registry file is present on the server.
Sorry, if it is not totally clear. In learning phase of ELK.
Thanks in advance.