Hi, I'm setting up a test environment where i want Winlogbeat and packetbeat to send Windows event logs to Elasticsearch through Logstash.
I need to know where do i suppose to enable ILM? on Beats side or logstash?
I've loaded the templates by enabling elasticsearch output in beats configuration.
When i set the output to logstash, the index it creates for Winlogbeat doesn't end with increamental number and eventually fails to rollover by policy.
Thanks for your reply @rugenl
Is there a way to get the first index created automatically?
Configuration is quite confusing actually. With the above config that i pasted before, index gets created in ES but it doesn't have an aliases associated.
No, there doesn't seem to be a way (in elasticsearch anyway) to create the initial index. This is similar to a case/discussion I had with Elastic
Depending on your environment and depth of devops structure, things might be possible. Say you were automating deployment of beats, you could possibly automate the template and bootstrap index creation.
Yes, it is confusing. I had a lot of problems with date math in index names. Yes, if you don't bootstrap the index, the initial index is a single index, neither old or new style rollover. And it probably duplicates the is_write_alias you want, so it's in the way of creating the bootstrap index.
ILM came out after we had planned our stack, it was too much of a crunch to learn it to implement. 60-90 days into our stack, we were creating over 60 indices a day, which isn't good. It took about a month to mostly convert to ILM, with a few bumps along the way.
Thanks @rugenl
I was able to create ILM supported indexes in ES through logstash using following config. So far its working fine.
Beats:
While the beat service was stopped, added following to the config, enabled ES output for setting up dashboard /Index management and removed / reverted output to LS when done.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.