Hi,
I have ELK stack working well with Logstash. Input is Syslog.
Just trying out winlogbeat in from Windows server to CentOS (ELK) server not works.
Checking indices, I can see all but, unable to view in Kibana.
Need help how to configure correct settings in logstash config.
Here is logstash config.
input {
beats {
port => 5443
type => "log"
}
udp {
port => 5514
type => syslog
}
}
filter {
if [type] == "syslog" {
grok {
match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:[%{POSINT:syslog_pid}])?: %{GREEDYDATA:syslog_message}" }
add_field => [ "received_at", "%{@timestamp}" ]
add_field => [ "received_from", "%{host}" ]
}
date {
match => [ "syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]
}
}
}
output {
elasticsearch { hosts => ["localhost:9200"] }
stdout { codec => rubydebug }
}
+++++++++++++++++++++++++++++++++++++++++++++++++++
curl -XGET "http://localhost:9200/_cat/indices?v"
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size
yellow open logstash-2017.12.30 y9YI3we-STKscYmYqg-XgQ 5 1 0 0 955b 955b
red open logstash-2018.04.01 0igJRyd2Qwi8-woLr5SZ3g 5 1 580 0 2.7mb 2.7mb
red open winlogbeat-6.2.4-2018.04.18 gUqSMxaWQO-0gG9rzp0FOQ 3 1
yellow open winlogbeat-6.2.4-2017.12.22 0rX2D_1sQsKNa1m78KyjPw 3 1 300 0 792.1kb 792.1kb
yellow open .kibana cJgmLTRyTUqvJw6UzvC9Eg 1 1 3 0 52kb 52kb
yellow open logstash-2017.12.31 HVbJaMekSF20Set0LlOa-Q 5 1 0 0 955b 955b
red open %{[@metadata][beat]}-2018.04.21 rc2QizN9SZmPU69UVKn2tg 5 1 0 0 648b 648b
red open logstash-2017.12.23 5E4iR04zSIqKLsaQxF6tQA 5 1 52 0 451.2kb 451.2kb
yellow open logstash-2018.04.18 v2qTfqSKTeeS6-1nxpBW5Q 5 1 49985 0 10mb 10mb
red open winlogbeat-6.2.4-2018.04.20 NwAEDWaPQZiyNpvkQpRfug 3 1
red open winlogbeat-6.2.4-2018.04.19 Ug67pfGKT6GHNYdjBRUDSQ 3 1
yellow open logstash-2018.04.21 LX_DTsLOTU2dDpF_oFfgtQ 5 1 98130 0 39.7mb 39.7mb
yellow open winlogbeat-6.2.4-2018.04.01 ts6px3TiRVSdQoAqumcwJw 3 1 414 0 1.1mb 1.1mb