I have a problem with the Logstash service constantly restarting and never sending data elasticsearch. There must be a bad config or a file missing in a location that it is set to read on startup. If I run manually, Logstash starts and sends data to elasticsearch correctly.
I did do a bit of reading and found that the .conf files are meant to be in /etc/logstash/conf.d not /etc/Logstash which is where I had them, but I still have issues even after moving the files. Is there a log file to check for errors? Also, is there a place to download the default .yml and .conf files located in the /etc/logstash/ directory so I copy replace any that I might have updated incorrectly.
I am not sure what changed but logs are now arriving at Elastic and starts after a reboot. The logstash services still reboots after a few minutes but doesn't appear to impact log shipping.
The problem I am still having issues with is monitoring Logstash in the elastic/kibana monitoring dashboard.
As you can see I have been able to colelct Elasticsearch, Kibana, Filebeat and Winlogbeat monitring data from different hosts but have not had any success with Logstash.
Can anyone suggest some solutions - my configuration file with the monitoring section is attached.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.