I have just created a new install of ELK 6.1.0 and am trying to use Filebeat to ship IIS logs to logstash. The ELK stack appears to be working and the filebeat service has started. I've vreated firrewall exceptions on my ELK server for ports 9200, 9300, 5601, 5.44. Below are my settings:
After browsing to a couple of outr internal web sites I've gone into Kibana and I cannot create any Index patterns as it "Couldn't find any Elasticsearch data".
2017-12-22T09:34:04Z WARN Filebeat is unable to load the Ingest Node pipelines for the configured modules because the Elasticsearch output is not configured/enabled. If you have already loaded the Ingest Node pipelines or are using Logstash pipelines, you can ignore this warning.
2017-12-26T16:51:57Z ERR Failed to publish events caused by: write tcp 10.20.0.19:65193->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-26T16:51:58Z ERR Failed to publish events: write tcp 10.20.0.19:65193->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T08:49:05Z ERR Failed to publish events caused by: write tcp 10.20.0.19:65195->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T08:49:06Z ERR Failed to publish events: write tcp 10.20.0.19:65195->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T09:22:58Z ERR Failed to publish events caused by: write tcp 10.20.0.19:65448->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T09:22:59Z ERR Failed to publish events: write tcp 10.20.0.19:65448->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T09:29:59Z ERR Failed to publish events caused by: write tcp 10.20.0.19:65464->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T09:30:00Z ERR Failed to publish events: write tcp 10.20.0.19:65464->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T09:31:04Z ERR Failed to publish events caused by: write tcp 10.20.0.19:65471->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T09:31:05Z ERR Failed to publish events: write tcp 10.20.0.19:65471->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T09:33:04Z ERR Failed to publish events caused by: write tcp 10.20.0.19:65486->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T09:33:05Z ERR Failed to publish events: write tcp 10.20.0.19:65486->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T09:36:01Z ERR Failed to publish events caused by: write tcp 10.20.0.19:65489->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T09:36:02Z ERR Failed to publish events: write tcp 10.20.0.19:65489->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T09:44:03Z ERR Failed to publish events caused by: write tcp 10.20.0.19:65507->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T09:44:04Z ERR Failed to publish events: write tcp 10.20.0.19:65507->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T09:45:58Z ERR Failed to publish events caused by: write tcp 10.20.0.19:65514->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T09:45:59Z ERR Failed to publish events: write tcp 10.20.0.19:65514->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T11:33:58Z ERR Failed to publish events caused by: write tcp 10.20.0.19:65518->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T11:33:59Z ERR Failed to publish events: write tcp 10.20.0.19:65518->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T11:35:03Z ERR Failed to publish events caused by: write tcp 10.20.0.19:49168->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T11:35:04Z ERR Failed to publish events: write tcp 10.20.0.19:49168->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T11:53:02Z ERR Failed to publish events caused by: write tcp 10.20.0.19:49169->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T11:53:03Z ERR Failed to publish events: write tcp 10.20.0.19:49169->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T11:55:02Z ERR Failed to publish events caused by: write tcp 10.20.0.19:49174->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T11:55:03Z ERR Failed to publish events: write tcp 10.20.0.19:49174->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T11:57:03Z ERR Failed to publish events caused by: write tcp 10.20.0.19:49202->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T11:57:04Z ERR Failed to publish events: write tcp 10.20.0.19:49202->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T12:04:05Z ERR Failed to publish events caused by: write tcp 10.20.0.19:49216->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T12:04:06Z ERR Failed to publish events: write tcp 10.20.0.19:49216->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T12:11:06Z ERR Failed to publish events caused by: write tcp 10.20.0.19:49219->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T12:11:07Z ERR Failed to publish events: write tcp 10.20.0.19:49219->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T12:14:01Z ERR Failed to publish events caused by: write tcp 10.20.0.19:49230->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T12:14:02Z ERR Failed to publish events: write tcp 10.20.0.19:49230->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T13:15:01Z ERR Failed to publish events caused by: write tcp 10.20.0.19:49238->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
2017-12-27T13:15:02Z ERR Failed to publish events: write tcp 10.20.0.19:49238->10.20.0.44:5044: wsasend: An existing connection was forcibly closed by the remote host.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.