You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
After restarting service , new index patterns: 340 fields
(changing hostname of both winlogbeat and packet)
The Problems
the old winlogbeat pattern still receive some winlogbeat data(the hostname is still unknown)
new index patterns seems to only accept packetbeat's data(the hostname shows correctly)
My questions
My question is as follows:
Do winlogbeat & packetbeat's data can send to the same index pattern? If so, how to distinguish them?
Why the hostname is still unknown after changing fields in winlogbeat.yml?
the cmd ./winlogbeat.exe setup -ewill prompt out error(like the pictures below), but cmd ./winlogbeat.exe -e or "Start-Service winlogbeat" works properly, did the system reject winlogbeat.yml after changing the hostname or did anything I miss?
Reply or discussion is appreciated, thanks!
The text was updated successfully, but these errors were encountered:
Yes, they can be sent to same index pattern. You can observe the fields to distinguish them.
Alternatively, you can setup different fields.logtag field for winlogbeat's and packetbeat's configuration.
The index naming format is stated in logstash's pipeline configuration in elastic.zip.
Check if the configuration for winlogbeat is valid and remember to restart the service
The error is expected since that command is used to setup Index Management which needs the configuration of output.elasticsearch. You could setup the index pattern via Kibana's web interface, so you don't need to run that command. Make sure that ./winlogbeat.exe -e shows no error message.
Hello TAs,
I managed to change fields.hostname after reading #16
When I restart services of winlogbeat and packetbeat,
Kibana create a new index pattern, yet the number of the fields seems different.
My winlogbeat.yml
#---------fields---------
fields:
hostname: _309551108
#----------kibana---------
setup.kibana:
host: "192.168.66.1:5601"
username: "admin"
username: "admin"
#------Logstash Output ----------
output.logstash:
hosts: ["192.168.66.1:5044"]
username: "admin"
password: "admin"
my first winlogbeat patterns: 679 fields
my first packetbeat patterns: 93 fields
After restarting service , new index patterns: 340 fields
(changing hostname of both winlogbeat and packet)
The Problems
the old winlogbeat pattern still receive some winlogbeat data(the hostname is still unknown)
new index patterns seems to only accept packetbeat's data(the hostname shows correctly)
My questions
My question is as follows:
./winlogbeat.exe setup -e
will prompt out error(like the pictures below), but cmd./winlogbeat.exe -e
or "Start-Service winlogbeat" works properly, did the system reject winlogbeat.yml after changing the hostname or did anything I miss?Reply or discussion is appreciated, thanks!
The text was updated successfully, but these errors were encountered: