I setup ELK server (kibana-4.6.1,logstash-2.4,elasticsearch-2.4) I have setup one index pattern (logstash-*) and using one time-field name (@timestamp)
When run Logstash with the -f flag /opt/logstash/bin/logstash -f /etc/logstash/conf.d/logstash.conf, I see in kibana new field (clientip. geoip) . When disable "ctrl-C" and "ctrl-D", I not see in kibana this field. Logstash is running in system
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.