I am new to Logstash, but I would like to use its capability of unix socket input, which comes very handy.
I have a program sending data to unix socket, i have that socket tested and i am 100% sure, that data are being sent there. I would like to retrieve these sockets with Logstash and for now just output them on stdout.
I have installed Logstash 6.3.2 from repository, running as service. My logstash.conf file in /etc/logstash/conf.d looks like this:
Unfortunately, I am getting these warning messages, even if socket is there, and i can output it with perl script. [2018-08-08T16:03:49,466][WARN ][logstash.inputs.unix ] Socket not present, wait for seconds for socket to appear {:client=>"/var/log/snort/snort_alert"}
and made it work. It can receive unix socket calls on the specified address, and passes them to Elastic search. Problems on Logstash side is solved out for now, now I have to take a look at Snort.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.