So basically I've built a lab environment on a vm. My goal is to send zeek logs to elk stack. Now I am very new to ubuntu, let alone install and config zeek and elk stack to work. I think my yml files are not being configured correctly but the problem can be a number of other things.
I was able to install zeek, elk stack and filebeat (following youtube videos) but the problem lies in connecting the two to work in conjunction. Where do I begin to look for solutions?
sudo: /etc/filebeat/modules.d/zeek.yml: command not found
ubuntu@ubuntu-virtual-machine:~$ sudo vim /etc/filebeat/modules.d/zeek.yml
ubuntu@ubuntu-virtual-machine:~$
ubuntu@ubuntu-virtual-machine:~$ sudo filebeat setup
Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: [error connecting to Elasticsearch at http://localhost:9200: Get "http://localhost:9200": dial tcp 127.0.0.1:9200: connect: connection refused]
ubuntu@ubuntu-virtual-machine:~$
Technically that is the Analytics Overview Page. The Home is the little "Home" button at the top.
The Elastic Stack and Kibana in particular have going through a lot of innovation / refinement recently so docs / video etc fall out of date quickly. The basic concepts remain the same though.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.