i tried to search for this type of problem for few days but i didn't find anything.
The infrastructure is like this
- 1 server with Wazuh-manager and Filebeat installed
- 1 server with Logstash, Elasticsearch and Kibana installed
What happens it's strange :
- everything is UP & running but i can't see no logs on Kibana
- first restart logstash or filebeat at 10.00 am
- all UP & running again
- second restart logstash or filebeat at 10.30 am
- on kibana it's possible to see only one log line concurrently with the first restart and then nothing again.
I tried to debug filebeat and it seems that all the log is passed to Logstash.
Filebeat configuration :
- type: log
I'm getting crazy about this, could you please help me to understand ?
Thank you so much