Hello,
-
I installed the Logstash logstash-2.3.2-1.noarch.rpm to CentOS.
-
Changed the config:
input {
beats {
port => 5044
}
}
output {
elasticsearch {
hosts => "srvis074.rccf.ru:9200"
manage_template => false
index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
document_type => "%{[@metadata][type]}"
}
} -
tested config:
[root@server bin]# ./logstash -f config.conf -t
Configuration OK -
Check installed beats plugin:
[root@server bin]# ./logstash-plugin list | grep beats
logstash-input-beats -
Started the logstash service:
[root@server bin]# service logstash status
logstash is running
But winlogbeats cannot connect to server:5044:
2016/06/10 08:41:36.480268 single.go:152: INFO send fail
2016/06/10 08:41:36.480268 single.go:159: INFO backoff retry: 1m0s
2016/06/10 08:42:37.475388 single.go:126: INFO Connecting error publishing events (retrying): dial tcp server:504
4: connectex: No connection could be made because the target machine actively refused it.
2016/06/10 08:42:37.476364 single.go:152: INFO send fail
2016/06/10 08:42:37.477341 single.go:159: INFO backoff retry: 1m0s
2016/06/10 08:43:38.472460 single.go:126: INFO Connecting error publishing events (retrying): dial tcp server:504
4: connectex: No connection could be made because the target machine actively refused it.
2016/06/10 08:43:38.474413 single.go:152: INFO send fail
2016/06/10 08:43:38.474413 single.go:159: INFO backoff retry: 1m0s