how can I, in the current version, include the Exim log and search entries via Kibana ?
About Filebeat I can transfer the log into Kibana, but there the assignment is not correct. So what do I have to set, that I search for a (example) email address in Kibana and get all entries from the main.log (from exim) - that match the email ?
Somehow I don't know what to do. I hope someone can help me.
Thank you very much for the nice welcome to the community.
So with Filebeat I import the main.log (from exim) into ELA/Kibana.
This is what my filebeat.yml looks like
filebeat.inputs:
# Each - is an input. Most options can be set at the input level, so
# you can use different inputs for various configurations.
# Below are the input specific configurations.
- type: log
# Change to true to enable this input configuration.
enabled: true
# Paths that should be crawled and fetched. Glob based paths.
paths:
- /var/log/exim/main.log
#- c:\programdata\elasticsearch\logs\*
But I would like to build it in a way that I have a column where the recipient is in it, in this
example test@test.de, and I can search for it via the search field.
Example: if I search for test@test.de, I would like to see all entries that have test@test.de as recipient.
And I do not know how to do that ? Probably a template is missing here or something.
Can you help me there ? I have already looked at the following link https://graemef.wordpress.com/ but I do not get anywhere.
2021-08-24T12:48:41.226+0200 ERROR instance/beat.go:989 Exiting: data path already locked by another beat. Please make sure that multiple beats are not sharing the same data path (path.data).
Exiting: data path already locked by another beat. Please make sure that multiple beats are not sharing the same data path (path.data).
I have set up the whole server again, module is now active and the error does not appear anymore. There seems to have been a misconfiguration somewhere.
How can I create a field in Kibana (Discover), where the email address from the exim log is in it ?
EDIT: It looks exactly the same in Kibana as it did before the exim4 module was activated.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.