I'm a begginer in ELK.
When i execute " service logstash configtest " I get this error message: "logstash: unrecognized service"
Although the logstash in already running.
This is my configuration :
input {
file {
path => "~/Bureau/log1.log"
type => "bind"
start_position => "beginning"
sincedb_path => "/dev/null"
}
}
filter {
if [type] == "bind" {
grok {
patterns_dir => "./patterns"
match => { "message" => "%{BINDT:timestamp} queries: client %{IP:ipaddress}#[0-9]{5} (%{HOSTNAME}): query: %{HOST:domain} IN %{DNSQUERY:query_type} (%{IP:ipaddress})" }
}
date {
match => [ "timestamp", "dd-MMM-YYYY HH:mm:ss.SSS" ]
}
}
}
output {
elasticsearch { hosts => ["localhost:9200"]
}
}
I would be grateful if you could help me.