Comments (6)
Hm, that certainly doesn't sound right. I just tested on one here:
[elk_user@sof-elk ~]$ sudo netstat -tulpn | grep 9995
udp 0 0 0.0.0.0:9995 0.0.0.0:* 2128/java
FWI, that should be reported (with a different PID, of course) even if the firewall is not open. I can't think of a reason that port would not be listening unless the entire logstash pipeline was crashed. Do you have anything in /var/log/logstash/logstash-plain.log
that may provide insight? You should be able to search for 9995
to get close.
I have the following on the same system as the netstat
command was run:
[2023-10-27T20:18:49,410][INFO ][logstash.inputs.udp ][main][945ed0156c99a0f45b4236702e814c70f307cd0e60221a10d3f8b12aa3bc11b0] Starting UDP listener {:address=>"0.0.0.0:9995"}
from sof-elk.
Also, the next release of the VM will use a new NetFlow ingest via filebeat. Not a help now, but that is running reliably in dev at this time.
from sof-elk.
Thanks for your help. I see some warnings about a cache file not being present in the logstash-plain.log. I'll do a reinstall first to exclude some weird user error on my side. Will report back when done to see if this issue was fixed for me.
from sof-elk.
sure thing. if you're seeing a template cache error, that's expected.
[2023-10-27T20:17:39,274][WARN ][logstash.codecs.netflow ] Template Cache does not exist {:file_path=>"/var/lib/logstash//netflow_templates.cache"}
let me know what you find!
from sof-elk.
On a clean install the listener is coming up just fine. Opened the port and the NetFlow data is received! No idea what was wrong on the previous install, but... fixed! Thanks for your pointers :)
from sof-elk.
OK great! Glad to hear. That input has historically been quite stable, but has become a little flaky recently. I suspect that's somewhat related to Elastic's move from the native input to Filebeat - which we'll have enabled instead for the future version (along with proper NetFlow v9 handling and much more!)
Glad it's working!
from sof-elk.
Related Issues (20)
- update filebeat inputs to use filestream HOT 2
- Fix Azure logstash parser in public release HOT 1
- Experiment with removing filebeat metadata HOT 2
- Evaluate fingerprinting to generate consistent document_id field HOT 2
- increase LS thread stack size HOT 1
- Typo in wiki HOT 1
- SOF-ELK integrate with opensearch HOT 1
- Use uncompressed filebeat shipping HOT 1
- Request for more Zeek JSON log support HOT 6
- Consider "time in pipeline" calculation HOT 1
- Broken link in Wiki/KAPE-Support HOT 1
- Wrong command line options in Wiki/log2timeline and Plaso HOT 1
- Broken link in Wiki/Virtual Machine README - Plaso HOT 1
- XFF_IP Field Not Handling Multiple IPs properly HOT 14
- convert iptables uptime to float
- Logstash randomly crashing when starting HOT 2
- update snare parsing
- domain-stats no longer works due to refactor HOT 3
- Azure Storage Logs StorageWrite not parsed HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from sof-elk.