I have built a syslog receiver using ELK 6.2.1, which works great.
Logstash receives syslog data and pushes it into ES and then I can use discover to see the logs coming in via Kibana.
I read somewhere that there are some default dashboards in filebeat that would allow me to see more in Kibana.
So I have installed filebeat on my single ELK server and I edited the following in filebeat.yml:
was changed to /var/lib/logstash/.log
In the Dashboards section:
In the Kibana section
I then ran the filebeat setup and installed it successfully (well I got no errors)
I then when into Kibana and saw lots of new dashboards but also got the following message on the top status bar:
No matching indices found: No indices match pattern "filebeat-*"
All my syslog data comes into Kibana with Logstash* and @timestamp.
Can anyone tell me what else I may need to do to the filebeat.yml file to be able to use the syslog dashboard with my syslog files within logstash?
All help is appreciated,