First of all sorry for my english I know it´s not the best one.
Well so, I installed logstash, elasicsearch and kibana on my debian 8 in Virtual box, and i Hvae a WatchWard where im receiving the logs from.
The problem is that i use the comand tcpdump port 5000 and im receiving pakets from my WatchWard, on my logstash file configuration it is configured to check te port 5000 and i dont know why it is not doing it, or maybe its my elasticsearch that its not doing its work i dunno, because if i configure my elastisearch to look up for local logs it shows me thoso so i dont know where is the problem.
if someone could help me it will be Awesome!
can you share the input and output blocks from your pipeline configuration? If they include credentials, please make sure to redact them.
the logs that Logstash emits can be helpful in determining many problems; where the logs end up dependent on how you've installed and are running Logstash, but these docs should help you find them.
typically, I include an additional output to stdout using the rubydebug codec while I'm standing up a new pipeline, which helps me see what Logstash is doing:
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.