I have lots of cisco switches and i've configured the devices to send syslogs to my logstash,the output plugin is elasticsearch.But it didn't take effect on some of the devices ,i have checked the status of the elasticsearch and logstash but i can not find any error.I do not know why.The configuration is as below.
i do not think so , i've tried to make a troubleshooting,and i found that when i change the input to udp , it does work! i thought it's the problem of the tcp input plugin.But i have no idea how to solve it
Hi are you still there ?
I had tried to using tcpdump , and i found that the syslog was indeed sent to the logstash . In the meantime , i configured the output as a file,if there is any pattern error , i can see that in the log,but now i can not find any error in the log,that's why i am sure it's not the problem of the pattern
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.