I added logstash user and restart logstash, still no results found in kibana
This is the tail of /var/ossec/logs/alerts/alerts.json
lsof /var/ossec/logs/alerts/alerts.json
It shows below result, does it mean it is reading the file now ?
If yes then, again there are no alert's in kibana discover.
Thanks and Regards,
Sardar S.
</blockquot
Yes I added this.
<a href="https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html" rel="nofollow" target="_blank" onmousedown="this.href='https://www.google.com/url?q\x3dhttps%3A%2F%2Fwww.elastic.co%2Fguide%2Fen%2Fbeats%2Ffilebeat%2Fcurrent%2Ffilebeat-template.html\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNF72ZRjhpbBXU_MO9zWncri92pGfA';return true;" onclick="this.href='https://www.google.com/url?q\x3dhttps%3A%2F%2Fwww.elastic.co%2Fguide%2Fen%2Fbeats%2Ffilebeat%2Fcurrent%2Ffilebeat-template.html\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNF72ZR
Hi Sardar,
Yes I added this.
Hi Sardar,The manager and ELK are installed in the same server? If they are, you don't need Filebeat and you have to change the Logstash configuration file. That is explained here: <a href="https://documentation.wazuh.com/current/installation-guide/installing-elastic-stack/elastic_server_rpm.html#logstash" rel="nofollow" target="_blank" onmousedown="this.href='https://www.google.com/url?q\x3dhttps%3A%2F%2Fdocumentation.wazuh.com%2Fcurrent%2Finstallation-guide%2Finstalling-elastic-stack%2Felastic_server_rpm.html%23logstash\x26sa\x3dD\x26sntz\x3d1\x26usg\x3dAFQjCNHOYp_z6YWibFgL_eNL7c4j9Mhq3Q';return true;" onclick="this.href='https://www.google.com/url?q\x3dhttps%3A%2F%2Fdocumentation.wazuh.com%2Fcurrent%2Finstallation-guide%2Finstalling-elastic-st