# Syslog, SSH Login Attempt and Nginx dashboard for Filebeat

**URL:** <https://discuss.elastic.co/t/syslog-ssh-login-attempt-and-nginx-dashboard-for-filebeat/150652>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 2, 2018, 6:43am UTC](https://discuss.elastic.co/t/syslog-ssh-login-attempt-and-nginx-dashboard-for-filebeat/150652 "2018-10-02T06:43:59Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 2, 2018, 6:43am UTC](https://discuss.elastic.co/t/syslog-ssh-login-attempt-and-nginx-dashboard-for-filebeat/150652/1 "2018-10-02T06:43:59Z")

</div>

Hello Team,

I am using Logstash pipeline so i can use dashboards available with Filebeat to visualize data in Kibana.  
I have followed the below link:

[https://www.elastic.co/guide/en/logstash/5.6/filebeat-modules.html](https://www.elastic.co/guide/en/logstash/5.6/filebeat-modules.html)

I am getting the logs on kibana dashboard using logstash pipeline for syslog, authlog and nginx and all the fields are also showing on kibana dashboard like s **ystem.auth.ssh.geoip.country\_name, system.auth.ssh.geoip.continent\_code** etc for authlog as well as nginx logs.

Please refer the below screenshot:

 ![Selection_036](https://us1.discourse-cdn.com/elastic/original/3X/d/4/d43e7212b87a248b54bfa327e706ef3f9101b013.png)

But i am not seeing any data in Nginx and syslogs dashboards of filebeat.

Can you please help me to troubleshoot the issue. In my testing environment its working fine.

Any assistance will be appreciated.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [October 2, 2018, 8:31am UTC](https://discuss.elastic.co/t/syslog-ssh-login-attempt-and-nginx-dashboard-for-filebeat/150652/2 "2018-10-02T08:31:27Z")

</div>

What is the name of index template you have set?  
Kibana dashboards are tied to `filebeat-*`. Is it possible you have configured it differently?

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 2, 2018, 9:01am UTC](https://discuss.elastic.co/t/syslog-ssh-login-attempt-and-nginx-dashboard-for-filebeat/150652/3 "2018-10-02T09:01:22Z")

</div>

Hello Noemi,

Thank you for your response.

> [@kvch](#):
>
> What is the name of index template you have set?

I have created separate template for each index and created separate indexes for auth.log, syslog and nginx access log. My template name are authlogs, syslog and nginxaccess

Below are the index patterns and templates names are also same:

![Selection_037](https://us1.discourse-cdn.com/elastic/original/3X/c/3/c3958a88a618c76c8564c5aa4ad493749adde16d.png)

In **filebeat-** \* index we are getting only our application logs.

I have created separate index for each log type so we can create separate dashboard for each log type with required field.

When we use single index for all logs then we create separate dashboard for each log type with required filed then dashboard showing blank line if selected filed data didn't match.

Can you please tell me how i can fix this issue?

One more question, if i use **filebeat-** \* index for my auth.log, syslog and nginx access logs then i will able to see the data on Filebeat syslog and nginx dashbord. I am right?

Thanks.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [October 2, 2018, 10:17am UTC](https://discuss.elastic.co/t/syslog-ssh-login-attempt-and-nginx-dashboard-for-filebeat/150652/4 "2018-10-02T10:17:35Z")

</div>

Yes, you can fix it by using `filebeat-*` for your modules logs.  
What is your Filebeat version?

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 2, 2018, 10:27am UTC](https://discuss.elastic.co/t/syslog-ssh-login-attempt-and-nginx-dashboard-for-filebeat/150652/5 "2018-10-02T10:27:29Z")

</div>

@noemie,

> [@kvch](#):
>
> What is your Filebeat version?

I am using ELK 6.4.0 as well as beat (Filebeat, Metricbeat) 6.4.0

> [@kvch](#):
>
> Yes, you can fix it by using `filebeat-*` for your modules logs.

I am not using filebeat modules, because i am using logstash and filebeat modules can't be used with logstash. i am using prospectors in filebeat and then logstash pipeline to ingest data.

There is one problem using filebeat-\* index for auth.log, syslog and nginx logs i.e all logs will be come in single index and even if we create separate dashboard on the basis of fields it will still show blank lines in each newly created dashboard. Which make searching difficult.

From above communication its seems that I don't have any other option now except by using **filebeat-** \* index for authlog and nginx log if i want to use filebeat dashboard of syslog and nginx.

If you can suggest any alternative that will be good for me.  
Thanks.

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 3, 2018, 4:53am UTC](https://discuss.elastic.co/t/syslog-ssh-login-attempt-and-nginx-dashboard-for-filebeat/150652/6 "2018-10-03T04:53:08Z")

</div>

Hello Team,

Can you please help me on above issue?

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [October 3, 2018, 7:56am UTC](https://discuss.elastic.co/t/syslog-ssh-login-attempt-and-nginx-dashboard-for-filebeat/150652/7 "2018-10-03T07:56:42Z")

</div>

You can edit the dashboard files before you upload it to Kibana. Change `"index": "filebeat-*"` to `"index": "{{ your-index-name }}"` in the dashboard JSONs provided by Filebeat. Then upload the dashboard again.

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [October 3, 2018, 8:01am UTC](https://discuss.elastic.co/t/syslog-ssh-login-attempt-and-nginx-dashboard-for-filebeat/150652/8 "2018-10-03T08:01:21Z")

</div>

@Noemi, Thank you for response.

I have made changes at my end. Now i am using filebeat-\* index for auth.log, syslog and nginx logs and now data is showing in Filebeat syslog and Nginx dashboard.

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 31, 2018, 8:01am UTC](https://discuss.elastic.co/t/syslog-ssh-login-attempt-and-nginx-dashboard-for-filebeat/150652/9 "2018-10-31T08:01:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
