Hi everyone,
I've done a bit of digging, but have not had much success.
I am using v5.6.4 of ELK
1ntgr@elk:~$ /usr/share/logstash/bin/logstash --version
logstash 5.6.4
1ntgr@elk:~$ /usr/share/kibana/bin/kibana --version
5.6.4
1ntgr@elk:~$ /usr/share/elasticsearch/bin/elasticsearch --version
Version: 5.6.4, Build: 8bbedf5/2017-10-31T18:55:38.105Z, JVM: 1.8.0_151
I am using python-logstash to input data and Lostash doesn't appear to be listening on the port (It is supposed to be listening on TCP/5958), despite everything appearing to be OK.
1ntgr@elk:~$ sudo /usr/share/logstash/bin/logstash -t -f /etc/logstash/conf.d/ --path.settings=/etc/logstash
Sending Logstash's logs to /var/log/logstash which is now configured via log4j2.properties
Configuration OK
My Logstash config file is:
input {
tcp {
port => 5958
codec => json
}
}
filter {
if [logger_name] == "python-logstash-logger" {
mutate {
replace => { "type" => "monitor" }
}
}
}
The ouput file is:
output {
if [logger_name] == "python-logstash-logger" {
elasticsearch {
hosts => ["localhost:9200"]
manage_template => false
index => "monitor-%{+xxxx.ww}"
}
}
}
I have tried restarting the services, and no errors occur.
EDIT:
The output of netstat -nl is:
1ntgr@elk:/var/log/logstash$ netstat -nl
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:443 0.0.0.0:* LISTEN
tcp 0 0 127.0.0.1:5601 0.0.0.0:* LISTEN
tcp6 0 0 ::1:9200 :::* LISTEN
tcp6 0 0 127.0.0.1:9200 :::* LISTEN
tcp6 0 0 ::1:9300 :::* LISTEN
tcp6 0 0 127.0.0.1:9300 :::* LISTEN
tcp6 0 0 :::22 :::* LISTEN
tcp6 0 0 127.0.0.1:9600 :::* LISTEN
Active UNIX domain sockets (only servers)
Proto RefCnt Flags Type State I-Node Path
unix 2 [ ACC ] STREAM LISTENING 99453 /run/user/1000/systemd/private
unix 2 [ ACC ] SEQPACKET LISTENING 10297 /run/udev/control
unix 2 [ ACC ] STREAM LISTENING 78889 /run/snapd.socket
unix 2 [ ACC ] STREAM LISTENING 78890 /run/snapd-snap.socket
unix 2 [ ACC ] STREAM LISTENING 13703 /var/lib/lxd/unix.socket
unix 2 [ ACC ] STREAM LISTENING 16612 /var/run/fail2ban/fail2ban.sock
unix 2 [ ACC ] STREAM LISTENING 10291 /run/lvm/lvmpolld.socket
unix 2 [ ACC ] STREAM LISTENING 10296 /run/systemd/fsck.progress
unix 2 [ ACC ] STREAM LISTENING 10300 /run/lvm/lvmetad.socket
unix 2 [ ACC ] STREAM LISTENING 10301 /run/systemd/journal/stdout
unix 2 [ ACC ] STREAM LISTENING 13694 /run/acpid.socket
unix 2 [ ACC ] STREAM LISTENING 13865 @ISCSIADM_ABSTRACT_NAMESPACE
unix 2 [ ACC ] STREAM LISTENING 13699 /run/uuidd/request
unix 2 [ ACC ] STREAM LISTENING 13700 /var/run/dbus/system_bus_socket
unix 2 [ ACC ] STREAM LISTENING 60466 /run/systemd/private
I'm using Ubuntu 16.04 as the OS.
Any pointers would be really appreciated.
Thanks,