Microsoft-sentinel-logstash-output-plugin is installed on logstash (7.15.1) server Linux but is not listed and found by logstash : /usr/share/logstash/bin #./logstash-plugin list
Desired survivor size 8716288 bytes, new threshold 4 (max 6)
age 1: 5538184 bytes, 5538184 total
age 2: 1405952 bytes, 6944136 total
age 3: 1089512 bytes, 8033648 total
age 4: 1012560 bytes, 9046208 total
age 5: 416928 bytes, 9463136 total
age 6: 1213536 bytes, 10676672 total
Desired survivor size 8716288 bytes, new threshold 6 (max 6)
age 1: 5039672 bytes, 5039672 total
age 2: 1138760 bytes, 6178432 total
age 3: 1404496 bytes, 7582928 total
age 4: 1089512 bytes, 8672440 total
Successfully installed microsoft-sentinel-logstash-output-plugin-1.0.0
1 gem installed
error identify on log server logstash :
message=>"Unable to configure plugins: (PluginLoadingError) Couldn't find any output plugin named 'microsoft-sentinel-logstash-output-plugin'.
Are you sure this is correct? Trying to load the microsoft-sentinel-logstash-output-plugin output plugin resulted in this error: Unable to load the requested plugin named microsoft-sentinel-logstash-output-plugin of type output.
The plugin is not installed.",
Again, that is not the right way to do the install. The Microsoft documentation links to pages that explain how to build a package for an offline install.
Thanks,
Now i get this issue in log logstash after add config Output plugin sentinel :
Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError",
:message=>"Expected one of [A-Za-z0-9_-], [ \t\r\n], "#", "{" at line 226, column 48 (byte 6995) after output {\n if [client] {\n if [client] == "iis" {\n if [indexname] {\n microsoft-sentinel-logstash-output-plugin-1",
:backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:187:in initialize'", "org/logstash/execution/JavaBasePipelineExt.java:72:in initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:47:in initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:52:in execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:391:in block in converge_state'"]}
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.