How to use one elastic-agent on host where elastic stack is deployed to be as fleet server and filebeat collecting udp syslog messages? I red that elastic agent can be use for fleet server and data collection simultaneously.
I added integrations to default fleet server policy but i don't see open ports listening for syslog input messages.
Fleet server enrolled succesfully.
Could you help me, maybe i misunderstood something?
I added system, palo alto and juniper integration. Before i used it in 7.12.0 without fleet server and worked fine. After update to 7.14i started to have problems. I added integrations with the same settings as before update.
I restarted kibana process and then fleet server and integrations started to listen on port. Only palo alto integration doesnt show any logs in discovery logs-panw* pattern. I see port is open for this integration. Docs are incementing in logs-panw index but when i create pattern and then choose it in discover section i dont see any new logs.
The logs should be present inside of Kibana. You can select the Elastic Agent and click the Logs tab. Inside that tab it should show all the logs for that agent.
Probably need to get the logs from the system to see what is going on, I think there is some other issue occurring, because you should have logs in Kibana if data is shipping.
I left elastic agent started and after few hours ports where opened and everything started to work. I don't know why it's working that way? My OS is Debian
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.