molu8bits / squid-filebeat-kibana Goto Github PK
View Code? Open in Web Editor NEWFilebeat module for Squid access.log + Kibana dashboards. ELK 7.x
License: Apache License 2.0
Filebeat module for Squid access.log + Kibana dashboards. ELK 7.x
License: Apache License 2.0
I get a "Sorry, there was an error" Saved objects file format is invalid and cannot be imported. Any suggestions?
Hello, I followed all the steps, it shows me the logs of the first day but today I generated the squid logs again and it did not show me the generated ones, it is as if they are not reloaded, any ideas?
I have got to the point when you import 01_visualisations_All.json and I received this error.
Import failed
Failed to import 7 of 7 objects. Import failed
Could not locate that index-pattern-field (id: squid.access.squid_request_status) Could not locate that index-pattern-field (id: squid.access.request_url) Could not locate that index-pattern-field (id: squid.access.dst_host) Could not locate that index-pattern-field (id: squid.access.src_ip) Could not locate that index-pattern-field (id: squid.access.http_status_code) Could not locate that index-pattern-field (id: squid.access.http_method) Could not locate that index-pattern-field (id: squid.access.dst_host)
Thanks for the help
I've just installed ELK 7.11 (noob with it). I have squid3 for a while.
I've installed filebeat on my squid server, using the files from this repo.
Everything seems good except geoip. What did I missed ?
Hi there,
I used the module in a test environment, and I think it is well-done. Are you planning to open a PR to elastic/beats?
Kind regards,
Mirko
No matter what I do my location values are not a geo_point
I followed the install instructions without encountering any errors yet the dashboard won't populate with data. Watching "live stream" in the logs shows that data is coming in from squid server through filebeat but we are seeing the following "squid.access.error.message" "Provided Grok expressions do not match field value:". Here is a sample message that we see that error with, but it happens for everything coming in (IP masked for security):
1561001136.756 0 172.XXX.XXX.64 TAG_NONE/400 4437 NONE error:invalid-request - HIER_NONE/- text/html
OS: Centos 7.7
ElasticSearch: 7.3.2-1
Kibana: 7.3.2-1
Filebeat: 7.3.2-1
Please let me know if I need to provide more data.
Thank you,
Should this also support the 10 native fields for the squid native access?
https://wiki.squid-cache.org/Features/LogFormat
Perhaps that would be squid.access.clf. and squid.access.native. for those instead.
being abit of a noob...the following steps are abit confusing:
in this step we configure filebit.yml.....
c.) configure /etc/filebeat/filebeat.yml - reference file placed in /etc/filebeat/filebeat.yml (change hosts ["elasticsearch.local"] in section output.elastichsearch to elastichsarch instance listening from filebeat host
in this step..it says to replace the file we configred....thinking this is a typo....
e.) Replace /etc/filebeat/filebeat.yml with filebeat/etc/fields.yml from repo. (Before run filebeat - Critical !). This file is a compiled version from 7.3 so the rest of functionality will work.
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.