All I have been playing with SO the last couple of days, first time user. I installed the ISO 16.04.4.3 and was able to get it up and running. I am currently only using it for the Bro syslog page and the Beats page. So far I have all my network equipment sending syslog data to it fine and I have 5 windows machines sending Winlogbeat data to it fine. The issue I am having is filebeat on linux Ubuntu machines. All my Ubuntu machines are 16.04.3 Desktop images running in ESXi 6.5. The Windows machines are a mix of different OS's and some are VMs and some are physical. I followed the install instructions for filebeat from SO links, I have validated that the service is running and that I can telnet to my SO server via 5044.
My filebeat config file
- type: log
# Change to true to enable this input configuration.
enabled: false
# Paths that should be crawled and fetched. Glob based paths.
paths:
- /var/log/auth.log
- /var/log/syslog
#- /var/log/*.log
#- c:\programdata\elasticsearch\logs\*
output.logstash:
# The Logstash hosts
hosts: ["
10.55.99.237:5044"]
bulk_max_size:1024
When I run sudo filebeat -e on the client I get
2018-08-07T12:15:37.572+0300 INFO instance/beat.go:225 Setup Beat: filebeat; Version: 6.3.2
2018-08-07T12:15:37.573+0300 INFO pipeline/module.go:81 Beat name: NetMon
2018-08-07T12:15:37.573+0300 INFO instance/beat.go:315 filebeat start running.
2018-08-07T12:15:37.573+0300 INFO registrar/registrar.go:117 Loading registrar data from /var/lib/filebeat/registry
2018-08-07T12:15:37.573+0300 INFO registrar/registrar.go:124 States Loaded from registrar: 0
2018-08-07T12:15:37.573+0300 WARN beater/filebeat.go:354 Filebeat is unable to load the Ingest Node pipelines for the configured modules because the Elasticsearch output is not configured/enabled. If you have already loaded the Ingest Node pipelines or are using Logstash pipelines, you can ignore this warning.
2018-08-07T12:15:37.573+0300 INFO crawler/crawler.go:48 Loading Inputs: 1
2018-08-07T12:15:37.573+0300 INFO crawler/crawler.go:82 Loading and starting Inputs completed. Enabled inputs: 0
2018-08-07T12:15:37.574+0300 INFO cfgfile/reload.go:122 Config reloader started
2018-08-07T12:15:37.574+0300 INFO [monitoring] log/log.go:97 Starting metrics logging every 30s
2018-08-07T12:15:37.574+0300 INFO cfgfile/reload.go:214 Loading of config files completed.
2018-08-07T12:16:07.576+0300 INFO [monitoring] log/log.go:124 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":0,"time":{"ms":4}},"total":{"ticks":10,"time":{"ms":20},"value":10},"user":{"ticks":10,"time":{"ms":16}}},"info":{"ephemeral_id":"73670594-2f1a-48da-ba68-eacc1a12ba40","uptime":{"ms":30011}},"memstats":{"gc_next":4473924,"memory_alloc":2987936,"memory_total":2987936,"rss":21241856}},"filebeat":{"harvester":{"open_files":0,"running":0}},"libbeat":{"config":{"module":{"running":0},"reloads":1},"output":{"type":"logstash"},"pipeline":{"clients":0,"events":{"active":0}}},"registrar":{"states":{"current":0}},"system":{"cpu":{"cores":2},"load":{"1":0,"15":0,"5":0.02,"norm":{"1":0,"15":0,"5":0.01}}}}}}
I did not read anywhere that I would need to do extra configuration steps in SO for filebeat when Winlogbeat works out of the box.
Any help would be greatly appreciated