I am trying to ingest DNSServer Analytics logs to my ELK stack (V-8.14) but the logs are not getting ingested, below is the configurations i added in my elastic-agent.yml file:
Are you using filebeat or the integration to try this out?
Something to check out is if you have the events enabled, since DNS Analytical events are disabled by default. You need to follow the guide in order to enable them.
I was able to get the DNSServer Analytics data with ETW configuration,
but observed that the data stops when elastic agent restarts.
when i investigate i see error log that :
Input 'etw' failed with: realtime session could not be created: session already exists: Cannot create a file when that file already exists.
so etw creates a session and collects data, but when agent is restarted, it is not able create a new session or get data from existing session.
"When specifying a provider, a new session is created. This controls the name for the new ETW session it will create. If not specified, the session will be named using the provider ID prefixed by 'Elastic-'.":
According to the configuration @Mario_22 posted - the Session-Name is not prefixed with "Elastic-" (so a "provider was specified"..?)
And according to the error-message @suhasbhatt101 provided there already exists a session.. (so "a new session is created")
Seems something got messed up with the specification of the ETW-Providers?
Maybe this helps:
how many sessions there are. And it seems that restarting the integration and DNS settings will allow connecting to the session, or will create a new one.
In my case, something was blocking (or duplicating the session)
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.