I need some help on process monitor
ex: datamonitor.exe process from logstash which plugin i need to use.
wmi plugin is not working.
and more over we are getting the status of process.state as running only.whenever if stops how can i monitor from elk.
please help on this
Welcome! By WMI plugin, which plugin do you mean? Is there are particular error you are seeing in the logs?
Logstash stopped processing because of an error: (LoadError) load error: win32ole/win32ole -- java.lang.UnsatisfiedLinkError: /usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/jruby-win32ole-0.8.5/lib/racob-x64.dll:
/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/jruby-win32ole-0.8.5/lib/racob-x64.dll: invalid ELF header. Am getting this error how to enable process monitor in elk.logstash is stopping automatically if am using wmi plugin
please help me with the solution
Ok Thanks @strawgate but how can i monitor from linux server for process from elk
You could look at deploying elastic agent or one of the beats like metricbeat into the device that has the process running
I would say the same, EA or MB, however if you need something specific to monitor you can use a pearl script and run it with the exec input plugin. I'm pretty sure MB will be enough with the system module.
Hi Rios can you send me the pearscript with exec plugin .
From elastic agent we enabled the from system integration process but we are facing whenever the process is stopped in server we are not getting any stopped state and showing as running .Kindly help me on this
I don't have the script, you can write it, or run:
ps aux | grep datamonitor.exe
Can we someone help me one adding condition inside system -> process integration for to get correct state to monitor process of .exe
From linux server how can we enable this process?
For Elastic Agent?
Have you tried including your process in the processes list?