Logstash not parsing logstash-tutorial.log

(w0lf) #1

Hello All,
I have installed logstash and filebeat as per the tutorial on my centos 7 machine. I have followed the example at https://www.elastic.co/guide/en/logstash/6.2/advanced-pipeline.html
However when I run it as per the tutorial its not parsing the sample data.
Below are the configuration details

Paths that should be crawled and fetched. Glob based paths.

- /var/log/logstash-tutorial.log


Array of hosts to connect to.

#hosts: ["localhost:9200"]


The Logstash hosts

hosts: ["localhost:5044"]

Logstash - first-pipeline.conf

input {
beats {
port => "5044"
filter {
grok {
match => { "message" => "%{COMBINEDAPACHELOG}"}
output {
stdout { codec => rubydebug }

Filebeat - /data/registery is empty

As per the tutorial I am starting filebeat
sudo ./filebeat -e -c filebeat.yml -d "publish"

Logstash -
sudo logstash -f first-pipeline.conf --config.reload.automatic

There is nothing in the logs.

(Mark Walkom) #2

Is Logstash not showing anything in stdout?

(w0lf) #3

nope and I just left it there and configured it for apache logs and it worked fine. Do not know what was wrong with the one I reported.

(system) #4

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.