Hello,thanks for your reply.Regarding the first command the result is:
# systemctl status filebeat
System has not been booted with systemd as init system (PID 1). Can't operate.
Failed to connect to bus: Host is downRegarding the 2nd2023-05-17T09:32:55.956Z INFO instance/beat.go:645 Home path: [/usr/share/filebeat] Config path: [/etc/filebeat] Data path: [/var/lib/filebeat] Logs path: [/var/log/filebeat]
2023-05-17T09:32:55.957Z INFO instance/beat.go:653 Beat ID: 100fedbc-051b-47c8-86ad-0bb7e4e0e3da
2023-05-17T09:32:55.957Z INFO [index-management] idxmgmt/std.go:184 Set output.elasticsearch.index to 'filebeat-7.10.2' as ILM is enabled.
2023-05-17T09:32:55.958Z INFO eslegclient/connection.go:99 elasticsearch url: https://wazuh.indexer:9200
2023-05-17T09:32:55.978Z INFO [esclientleg] eslegclient/connection.go:314 Attempting to connect to Elasticsearch version 7.10.2Best regards,
/# service
filebeat restart
* Restarting Filebeat sends log files to Logstash or directly to
Elasticsearch. filebeat
2023-05-22T11:01:50.295+0200
INFO instance/beat.go:645 Home path:
[/usr/share/filebeat] Config path: [/etc/filebeat] Data path:
[/var/lib/filebeat] Logs path: [/var/log/filebeat]
2023-05-22T11:01:50.303+0200 INFO instance/beat.go:653
Beat ID: ****
2023-05-22T11:01:50.303+0200 INFO [beat]
instance/beat.go:981 Beat info
{"system_info": {"beat": {"path":
{"config": "/etc/filebeat", "data":
"/var/lib/filebeat", "home":
"/usr/share/filebeat", "logs": "/var/log/filebeat"},
"type": "filebeat", "uuid": "****"}}}
2023-05-22T11:01:50.303+0200 INFO [beat]
instance/beat.go:990 Build info
{"system_info": {"build": {"commit":
"****", "libbeat": "7.10.2", "time":
"2021-01-12T22:10:33.000Z", "version": "7.10.2"}}}
2023-05-22T11:01:50.304+0200 INFO [beat]
instance/beat.go:993 Go runtime info
{"system_info": {"go":
{"os":"linux","arch":"amd64","max_procs":2,"version":"go1.14.12"}}}
2023-05-22T11:01:50.304+0200 INFO [beat]
instance/beat.go:997 Host info
{"system_info": {"host":
{"architecture":"x86_64","boot_time":"2023-05-10T13:13:30+02:00","containerized":true,"name":"wazuh.manager","ip":["****"],"kernel_version":"4.15.0-211-generic","mac":["02:42:ac:14:00:02"],"os":{"family":"debian","platform":"ubuntu","name":"Ubuntu","version":"20.04.5
LTS (Focal
Fossa)","major":20,"minor":4,"patch":5,"codename":"focal"},"timezone":"CEST","timezone_offset_sec":7200,"id":"****"}}}
2023-05-22T11:01:50.305+0200 INFO [beat]
instance/beat.go:1026 Process info
{"system_info": {"process":
{"capabilities": {"inheritable":null,"permitted":["chown","dac_override","fowner","fsetid","kill","setgid","setuid","setpcap","net_bind_service","net_raw","sys_chroot","mknod","audit_write","setfcap"],"effective":["chown","dac_override","fowner","fsetid","kill","setgid","setuid","setpcap","net_bind_service","net_raw","sys_chroot","mknod","audit_write","setfcap"],"bounding":["chown","dac_override","fowner","fsetid","kill","setgid","setuid","setpcap","net_bind_service","net_raw","sys_chroot","mknod","audit_write","setfcap"],"ambient":null},
"cwd": "/", "exe":
"/usr/share/filebeat/bin/filebeat", "name":
"filebeat", "pid": ****, "ppid": ****,
"seccomp":
{"mode":"filter","no_new_privs":false},
"start_time": "2023-05-22T11:01:49.710+0200"}}}
2023-05-22T11:01:50.305+0200 INFO
instance/beat.go:299 Setup Beat: filebeat; Version: 7.10.2
2023-05-22T11:01:50.306+0200 INFO
eslegclient/connection.go:99 elasticsearch url: https://wazuh.indexer:9200
2023-05-22T11:01:50.307+0200 INFO [publisher]
pipeline/module.go:113 Beat name: wazuh.manager
2023-05-22T11:01:50.309+0200 INFO
beater/filebeat.go:117 Enabled modules/filesets: wazuh (alerts,
archives), ()
Config OK
Filebeat is not running
# cat
/var/log/filebeat/filebeat
2023-05-22T11:02:20.421+0200 INFO
instance/beat.go:645 Home path: [/usr/share/filebeat] Config
path: [/etc/filebeat] Data path: [/var/lib/filebeat] Logs path:
[/var/log/filebeat]
2023-05-22T11:02:20.421+0200 INFO
instance/beat.go:653 Beat ID: ****
2023-05-22T11:02:20.422+0200 INFO [seccomp]
seccomp/seccomp.go:124 Syscall filter successfully
installed
2023-05-22T11:02:20.422+0200 INFO [beat]
instance/beat.go:981 Beat info
{"system_info": {"beat": {"path":
{"config": "/etc/filebeat", "data":
"/var/lib/filebeat", "home":
"/usr/share/filebeat", "logs":
"/var/log/filebeat"}, "type": "filebeat",
"uuid": "100fedbc-051b-47c8-86ad-0bb7e4e0e3da"}}}
2023-05-22T11:02:20.422+0200 INFO [beat]
instance/beat.go:990 Build info
{"system_info": {"build": {"commit":
"aacf9ecd9c494aa0908f61fbca82c906b16562a8", "libbeat":
"7.10.2", "time": "2021-01-12T22:10:33.000Z",
"version": "7.10.2"}}}
2023-05-22T11:02:20.422+0200 INFO [beat]
instance/beat.go:993 Go runtime info
{"system_info": {"go":
{"os":"linux","arch":"amd64","max_procs":2,"version":"go1.14.12"}}}
2023-05-22T11:02:20.422+0200 INFO [beat]
instance/beat.go:997 Host info
{"system_info": {"host":
{"architecture":"x86_64","boot_time":"2023-05-10T13:13:30+02:00","containerized":true,"name":"wazuh.manager","ip":["****"],"kernel_version":"4.15.0-211-generic","mac":["02:42:ac:14:00:02"],"os":{"family":"debian","platform":"ubuntu","name":"Ubuntu","version":"20.04.5
LTS (Focal
Fossa)","major":20,"minor":4,"patch":5,"codename":"focal"},"timezone":"CEST","timezone_offset_sec":7200,"id":"*****"}}}
2023-05-22T11:02:20.422+0200 INFO [beat]
instance/beat.go:1026 Process info
{"system_info": {"process":
{"capabilities": {"inheritable":null,"permitted":["chown","dac_override","fowner","fsetid","kill","setgid","setuid","setpcap","net_bind_service","net_raw","sys_chroot","mknod","audit_write","setfcap"],"effective":["chown","dac_override","fowner","fsetid","kill","setgid","setuid","setpcap","net_bind_service","net_raw","sys_chroot","mknod","audit_write","setfcap"],"bounding":["chown","dac_override","fowner","fsetid","kill","setgid","setuid","setpcap","net_bind_service","net_raw","sys_chroot","mknod","audit_write","setfcap"],"ambient":null},
"cwd": "/", "exe":
"/usr/share/filebeat/bin/filebeat", "name":
"filebeat", "pid": ****, "ppid": ****,
"seccomp":
{"mode":"filter","no_new_privs":true},
"start_time": "2023-05-22T11:02:19.850+0200"}}}
2023-05-22T11:02:20.422+0200 INFO
instance/beat.go:299 Setup Beat: filebeat; Version: 7.10.2
2023-05-22T11:02:20.423+0200 INFO
eslegclient/connection.go:99 elasticsearch url: https://wazuh.indexer:9200
2023-05-22T11:02:20.423+0200 INFO [publisher]
pipeline/module.go:113 Beat name: wazuh.manager
2023-05-22T11:02:20.426+0200 INFO
beater/filebeat.go:117 Enabled modules/filesets: wazuh (archives,
alerts), ()
2023-05-22T11:02:20.427+0200 INFO
instance/beat.go:455 filebeat start running.
2023-05-22T11:02:20.430+0200 INFO memlog/store.go:119
Loading data file of '/var/lib/filebeat/registry/filebeat'
succeeded. Active transaction id=****
2023-05-22T11:02:20.634+0200 INFO memlog/store.go:124
Finished loading transaction log file for '/var/lib/filebeat/registry/filebeat'.
Active transaction id=****
2023-05-22T11:02:20.634+0200 INFO [registrar]
registrar/registrar.go:109 States Loaded from
registrar: 1
2023-05-22T11:02:20.634+0200 INFO [crawler]
beater/crawler.go:71 Loading Inputs: 2
2023-05-22T11:02:20.635+0200 INFO log/input.go:157
Configured paths:
[/var/ossec/logs/alerts/alerts.json]
2023-05-22T11:02:20.635+0200 INFO [crawler]
beater/crawler.go:141 Starting input (ID: ****)
2023-05-22T11:02:20.635+0200 INFO log/input.go:157
Configured paths:
[/var/ossec/logs/archives/archives.json]
2023-05-22T11:02:20.635+0200 INFO [crawler]
beater/crawler.go:141 Starting input (ID: ***)
2023-05-22T11:02:20.635+0200 INFO [crawler]
beater/crawler.go:108 Loading and starting Inputs
completed. Enabled inputs: 2
2023-05-22T11:02:20.692+0200 INFO
beater/filebeat.go:515 Stopping filebeat
2023-05-22T11:02:20.692+0200 INFO
beater/crawler.go:148 Stopping Crawler
2023-05-22T11:02:20.692+0200 INFO
beater/crawler.go:158 Stopping 2 inputs
2023-05-22T11:02:20.698+0200 INFO [crawler]
beater/crawler.go:163 Stopping input: ****
2023-05-22T11:02:20.702+0200 INFO [crawler]
beater/crawler.go:163 Stopping input: ****
2023-05-22T11:02:20.702+0200 INFO input/input.go:136
input ticker stopped
2023-05-22T11:02:20.702+0200 INFO input/input.go:136
input ticker stopped
2023-05-22T11:02:20.708+0200 INFO
beater/crawler.go:178 Crawler stopped
2023-05-22T11:02:20.708+0200 INFO [registrar]
registrar/registrar.go:132 Stopping Registrar
2023-05-22T11:02:20.708+0200 INFO [registrar]
registrar/registrar.go:166 Ending Registrar
2023-05-22T11:02:20.708+0200 INFO [registrar]
registrar/registrar.go:137 Registrar stopped
2023-05-22T11:02:20.717+0200 INFO
instance/beat.go:461 filebeat stopped.