I just installed 6.1.1 of all three. I then setup Palo Alto to send syslog over udp/5514.
I configured the logstash config file for input from syslog to output elasticsearch.
Kibana is giving me the index error and there is no button to create an index like earlier versions i've used.
I know syslog traffic is coming in to the server but I don't know where its stored and there is no ability to create the first index that is required to get past this fresh install.
Am I missing something?