I am running the elk stack on 1 ubuntu device along with filebeat, and metricbeat and this device is showing up fine with syslog data and as a host. Im running winlogbeat on another device, and shipping the logs through logstash . The events from the windows machine are showing up under the events tab, but its not showing up as a host, and it claims to only get event from filebeat, even though it clearly is getting events from the windows machine, which only runs winlogbeat.
As you can see there are events from 2 different hosts, but only teleit-vm is showing up properly
Any ideas what is the problem here?
I have tried running this
.\winlogbeat.exe setup --index-management -E output.logstash.enabled=false -E 'output.elasticsearch.hosts=["172.16.10.20:9200"]' but i get the error
no connection could be made because the host actively refused it
I have checked the firewall on the ubuntu machine and it is disabled. i can ping it just fine I get the occasional crash on the Elasticsearch but the errors are just gigantic and quite frankly impossible to sort through.
heres a pastebin of a small snippet of the error... https://pastebin.com/qstux58p
Read that this could be a resource problem, but i just gave the VM 64gb memory and it still breaks as soon as i go to kibana on firefox