Since this situation feels like related to elasticsearch index, I post it here,
I have installed and working HCP 1.9.1
After that, when I try the learning and training tutorial described at:
https://docs.hortonworks.com/HDPDocuments/HCP1/HCP-1.9.1/runbook-overview/index.html
I get to the point where I'm not able to see the Squid log in elasticsearch index,
I'm really stuck at here,
default index was created, my work around was to use this: logstash default index - Pastebin.com
and I also use this: Squid demo index for HCP Hortonworks - Pastebin.com
tcpdump -A -i ens192 src <nifi-ipaddress> from my single elasticsearch host shows this:
12:16:16.224880 IP HCP10-DataSource1.33810 > HCP9-MetronSearch1.ircu-3: Flags [P.], seq 1490977535:1490977718, ack 1135751061, win 31088, options [nop,nop,TS val 10936402 ecr 10787491], length 183
2. E....[@.@.'.
- ..
- ......X...C./...yp.......
- ...R...............y.
- nifi-squid....u0......squid.......................v..6-.........h1557378975.223 232 127.0.0.1 TCP_MISS/302 280 GET http://www.atmape.ru/ - HIER_DIRECT/36.86.63.182 -
- 12:16:21.226164 ARP, Reply HCP10-DataSource1 is-at 00:50:56:99:6b:51 (oui Unknown), length 46
- .........PV.kQ
- ...PV..4
- ....................
But no result found in Kibana,
Any help thank you!
