GithubHelp home page GithubHelp logo

molu8bits / squid-filebeat-kibana Goto Github PK

View Code? Open in Web Editor NEW
17.0 7.0 15.0 321 KB

Filebeat module for Squid access.log + Kibana dashboards. ELK 7.x

License: Apache License 2.0

filebeat squid kibana elk squid-access kibana-dashboard visualisations squid-filebeat-kibana elasticsearch visualisation

squid-filebeat-kibana's People

Contributors

molu8bits avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar

squid-filebeat-kibana's Issues

filebeat don't start

Filebeat don't want start (error). it don't want send logfiles

i saw troubeshooting but file "squid-fileds.yml" is missing

filebeat
squidfiled

dashboard

Hello, I followed all the steps, it shows me the logs of the first day but today I generated the squid logs again and it did not show me the generated ones, it is as if they are not reloaded, any ideas?

Map Dashboard not showing any data

Hi there,
Please, could you have a look on your maps dashboard? I setup a new instance but not showing any data as display bellow:

squid

Many thanks.

Imported Failed Failed to import 7 of 7 objects. Import failed

I have got to the point when you import 01_visualisations_All.json and I received this error.
Import failed
Failed to import 7 of 7 objects. Import failed

Could not locate that index-pattern-field (id: squid.access.squid_request_status) Could not locate that index-pattern-field (id: squid.access.request_url) Could not locate that index-pattern-field (id: squid.access.dst_host) Could not locate that index-pattern-field (id: squid.access.src_ip) Could not locate that index-pattern-field (id: squid.access.http_status_code) Could not locate that index-pattern-field (id: squid.access.http_method) Could not locate that index-pattern-field (id: squid.access.dst_host)

Thanks for the help

geoip

No matter what I do my location values are not a geo_point

Probably my bad

I followed the install instructions without encountering any errors yet the dashboard won't populate with data. Watching "live stream" in the logs shows that data is coming in from squid server through filebeat but we are seeing the following "squid.access.error.message" "Provided Grok expressions do not match field value:". Here is a sample message that we see that error with, but it happens for everything coming in (IP masked for security):

1561001136.756 0 172.XXX.XXX.64 TAG_NONE/400 4437 NONE error:invalid-request - HIER_NONE/- text/html

OS: Centos 7.7
ElasticSearch: 7.3.2-1
Kibana: 7.3.2-1
Filebeat: 7.3.2-1

Please let me know if I need to provide more data.
Thank you,

config question

being abit of a noob...the following steps are abit confusing:

in this step we configure filebit.yml.....
c.) configure /etc/filebeat/filebeat.yml - reference file placed in /etc/filebeat/filebeat.yml (change hosts ["elasticsearch.local"] in section output.elastichsearch to elastichsarch instance listening from filebeat host

in this step..it says to replace the file we configred....thinking this is a typo....
e.) Replace /etc/filebeat/filebeat.yml with filebeat/etc/fields.yml from repo. (Before run filebeat - Critical !). This file is a compiled version from 7.3 so the rest of functionality will work.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.