Skip to content
This repository has been archived by the owner on Apr 16, 2021. It is now read-only.

securityonion-elastic: Logstash should include all inputs #1269

Closed
dougburks opened this issue Jun 22, 2018 · 3 comments
Closed

securityonion-elastic: Logstash should include all inputs #1269

dougburks opened this issue Jun 22, 2018 · 3 comments

Comments

@dougburks
Copy link
Contributor

Currently, if you have a master server and storage nodes, then logstash on the master server only consumes from syslog. This prevents sending beats and other inputs.

We need to ensure that Logstash includes all inputs. In the meantime, folks should be able to add inputs manually like the following:

sudo ln -sf ../conf.d.available/0006_input_beats.conf /etc/logstash/conf.d.redis.output/0006_input_beats.conf
sudo so-logstash-restart

For more information, please see:
https://groups.google.com/d/topic/security-onion/dQuiY1bTvg8/discussion

@dougburks dougburks changed the title Logstash should include all inputs securityonion-elastic: Logstash should include all inputs Aug 16, 2018
@dougburks
Copy link
Contributor Author

@dougburks
Copy link
Contributor Author

@dougburks
Copy link
Contributor Author

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant