I'm new to this Kibana/logstash stuff, and due to the current situation, so I'm seeking some help here.
Setting up Apache2 on Kibana/Logstash server so that I can get the following information from the web client that runs Apache/httpd, and able to send that information to Kibana (sys log), as well as generating a report or something.
- User login and logout time on website
I've done some research but still unable to get it configured correctly, I managed to get the ingest-user-agent and ingest-geoip.html installed.
On the Kibana's interface, I'm able to see Filebeat -> apache2.access.agent and other apache modules on the list from "Add a filter" but when i tried to use visualize, the information is not showing on the web.
What I'd like to know is:
1). Do I need to setup anything on agent? I can see agents running on Logstash.
2). Can someone give me the config that I need to use for filebeat, logstash etc?
I'd appreciate if someone can help me. Please let me know if you have any questions or concerns.
I've done checking the config i don't see anything wrong:
[root@m filebeat]# /usr/bin/filebeat.sh -configtest -e
2018/08/27 02:32:07.371161 beat.go:297: INFO Home path: [/usr/share/filebeat] Config path: [/etc/filebeat] Data path: [/var/lib/filebeat] Logs path: [/var/log/filebeat]
2018/08/27 02:32:07.371203 beat.go:192: INFO Setup Beat: filebeat; Version: 5.6.2
2018/08/27 02:32:07.371229 publish.go:228: WARN Support for loading more than one output is deprecated and will not be supported in version 6.0.
2018/08/27 02:32:07.371260 metrics.go:23: INFO Metrics logging every 30s
2018/08/27 02:32:07.371372 output.go:258: INFO Loading template enabled. Reading template file: /etc/filebeat/filebeat.template.json
2018/08/27 02:32:07.372128 output.go:269: INFO Loading template enabled for Elasticsearch 2.x. Reading template file: /etc/filebeat/filebeat.template-es2x.json
2018/08/27 02:32:07.372871 output.go:281: INFO Loading template enabled for Elasticsearch 6.x. Reading template file: /etc/filebeat/filebeat.template-es6x.json
2018/08/27 02:32:07.373560 client.go:128: INFO Elasticsearch url: http://localhost:9200
2018/08/27 02:32:07.373595 outputs.go:108: INFO Activated elasticsearch as output plugin.
2018/08/27 02:32:07.373655 logstash.go:90: INFO Max Retries set to: 3
2018/08/27 02:32:07.373709 outputs.go:108: INFO Activated logstash as output plugin.
2018/08/27 02:32:07.373804 publish.go:300: INFO Publisher name: m
2018/08/27 02:32:07.374080 async.go:63: INFO Flush Interval set to: 1s
2018/08/27 02:32:07.374099 async.go:64: INFO Max Bulk Size set to: 50
2018/08/27 02:32:07.374128 async.go:63: INFO Flush Interval set to: 1s
2018/08/27 02:32:07.374144 async.go:64: INFO Max Bulk Size set to: 2048