Hi,
I am using 6.5.4 version of elastic stack. (Filebeat - Logstash - Elasticsearch - Kibana).
filebeat was working fine. Enabled x-pack in ES and other related settings.
ELK - Able to start the services.
But Logstash is not listening on port 5044. Filebeat input.
No error message Logstash and in Elasticsearch.
Logstash config file.
input {
beats {
port => 5044
}
}
filter {
mutate {
copy => {
"[fields][log_prefix]" => "[@metadata][log_prefix]"
"[fields][log_idx]" => "[@metadata][index]"
"[fields][application]" => "[@metadata][application]"
}
}
}
output {
elasticsearch {
user => logstash_internal
password => x-pack-test-password
hosts => ["HOSTNAME:9200"]
manage_template => false
index => "%{[@metadata][log_prefix]}-%{[@metadata][index]}-%{+YYYY.MM.dd}"
}
stdout { codec => rubydebug }
}
Logstash Log
[2019-02-25T07:00:32,940][INFO ][logstash.pipeline ] Starting pipeline {:pipeline_id=>".monitoring-logstash", "pipeline.workers"=>1, "pipeline.batch.size"=>2, "pipeline.batch.delay"=>50}
[2019-02-25T07:00:33,301][INFO ][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=>{:removed=>[], :added=>[http://logstash_internal:xxxxxx@HOSTNAME:9200/]}}
[2019-02-25T07:00:33,490][WARN ][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=>"http://logstash_internal:xxxxxx@HOSTNAME:9200/"}
[2019-02-25T07:00:33,501][INFO ][logstash.outputs.elasticsearch] ES Output version determined {:es_version=>6}
[2019-02-25T07:00:33,502][WARN ][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document _type {:es_version=>6}
[2019-02-25T07:00:33,743][INFO ][logstash.outputs.elasticsearch] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["http://HOSTNAME:9200"]}
[2019-02-25T07:00:34,281][INFO ][logstash.pipeline ] Pipeline started successfully {:pipeline_id=>".monitoring-logstash", :thread=>"#<Thread:0x773be260 sleep>"}
[2019-02-25T07:00:34,413][INFO ][logstash.agent ] Pipelines running {:count=>1, :running_pipelines=>[:".monitoring-logstash"], :non_running_pipelines=>[:main]}
[2019-02-25T07:00:41,007][INFO ][logstash.agent ] Successfully started Logstash API endpoint {:port=>9600}
netstat -tunl | grep 5044 ID@HOSTNAME(PQ_Agility_1-7.5):/etc/logstash/conf.d 1
Can anyone help me on this?