Replies: 2 comments 14 replies
-
@mlater1 - thanks for providing the error.pfelk.log file. It appears that there are a few issues: First, the file structure should look like this:
Next, to troubleshoot, run the following:
Based on the provided error.pfelk.log, logstash stopped as a result of one of the files being placed in the incorrect location ( Once you fix the issue above (incorrect file location), there may be others based on your current file structure below with notes: /etc/pfelk/ |
Beta Was this translation helpful? Give feedback.
-
I might try removing that reference in 05-apps.conf later then since I have no need for openvpn logging.
Even with ufw disabled, I get the same results. |
Beta Was this translation helpful? Give feedback.
-
I did the manual install process and everything seemed to go smoothly but I can't seem to get any data from pfSense into pfelk and the dashboards are blank. I have an existing ELK stack so I made any necessary changes to the elasticsearch.yml and pipelines.yml files but did not overwrite them.
As a troubleshooting step I even added '*.* @127.0.0.1:5140' into my rsyslog conf but that didn't change anything.
I took a tcpdump on the pfelk host and the syslog logs are making it via udp 5140 but for some reason, they're not getting ingested into logstash. I've attached the error script output and I'm relatively new to ELK, so please excuse me if I've made a simple mistake. Any help is appreciated.
error.pfelk.log
Beta Was this translation helpful? Give feedback.
All reactions