Logstash issue with pfSense 2.2.2 (SOLVED)


(Killmasta93) #1

Hi,

I was wondering if someone could guide me or help me with this issue I
have been having. I think i know where im wrong i just dont know what do
about it. Alright So i have been following 2 guides to get my pfSense
to send all the logs. I am using lbuntu for the operating system.

So i did everything that the guide says and even the Kibana web
interface shows up but the part im stuck is on the logstash. I think the
part where im confused on the second guide is where he says i need to
put this other file pfsense2-2.grok into the patterns folder but I have
no idea where to add the patterns folder. And the pfsense2-2.grok https://gist.github.com/elijahpaul/f5f32d4e914dcb7fedd2

Because when i run tail -f /var/log/logstash/logstash.stdout

i get an outcome of "get pattern log not defined" see pics

and also im not sure why i am not getting dashboards for pfSense instead i get a kibana dashboard or a logstash dashboard

https://elijahpaul.co.uk/monitoring-pfsense-
2-1-logs-using-elk-logstash-kibana-elasticsearch/

Thank you








(Mark Walkom) #2

It's easier if you put the text stuff into gist/pastebin/etc and then link it, screenshots can be hard to read :smile:

The patterns directory is relative to the logstash binary. It's best if you use a full path to it to be safe.


(Killmasta93) #3

Hi Mark,
Thank you for replying so quick. My apologies on github im somewhat new to this stuff :smile: Here are the paste bins. So if i understood correctly i would open putty then type vim /opt/logstash/patterns/pfsense2-2.grok
Edit that file using this pastebin https://gist.github.com/elijahpaul/f5f32d4e914dcb7fedd2

then type sudo service logstash restart
then i try to run tail -f /var/log/logstash/logstash.stdout
but it gets stuck does not show error
http://s22.postimg.org/jjuhd7ikh/Clipboarder_2015_08_24_017.png :frowning:
http://pastebin.com/dtLYNiFQ 11-pfsense.config
http://pastebin.com/LJjTx6TH 01-inputs.config
http://pastebin.com/KpxYkPLg 10-syslog.conf

Thank you


(Killmasta93) #4

so i figured out what i did wrong for people who having trouble i will make a full tutorial on installing ELK after i get geoip working with curator on automatic deletion. What happened i had to join those 3 .conf and make it into one and call it logstash.conf and need to point my .grok files to the patterns directory on the logstash.conf


(Mark Walkom) #5

Sorry for not getting back to you on this.

You shouldn't need to merge the files, LS does that for you at run time.


(Killmasta93) #6

no worries, thanks for replying so the way i had it worked?


(Killmasta93) #7

yeah your completely right i just separated the files i think what i missed is to run service logstash restart

now its working also is there way to auto start logstash when the VM restarts?

Thank you


(Mark Walkom) #8

It should do that, but if not it depends on your OS and what manages the service.


(Killmasta93) #9

Thank you again :smile:


(system) #10