I installed for the first time elastic stack on centos 7, I want to collect different types of logs (firewalls logs through syslog, and windows logs through winlogbeat) and netflow v9.
I managed to collect and view windows logs through Winlogbeat, but when I add the configuration file "netflow.conf" in /etc/logstash/conf.d, logstash stops.
Apparently it is not possible to collect them all at once. So I deleted the conf file "beats.conf" and I left only "netflow.conf", I activated the netflow module with the command:
#bin/logstash --modules netflow --setup -M netflow.var.input.udp.port=2055 -M netflow.var.elasticsearch.hosts="localhost:9200"
I was able to collect it and visualize it on kibana . but, the netflow dashboard is not created on kibana.
To summarize, I would like to know please:
- How can I collect all these types of logs at once (must I change the path.data for each configuration file (netflow / beats / syslog))?
- How to create the dashboard for the netflow on Kibana?