docker-compose -f labs\beats\compose.yml up -d
http://localhost:5601
docker-compose -f labs\beats\filebeat-simplecsv.yml up -d
docker logs elkstack_filebeat-simplecsv_1 -f
Loading and starting Inputs completed. Enabled inputs: 1
cp data/simple-small-1.csv labs/beats/data/
Pipeline & dashboard
docker-compose -f labs\beats\filebeat-apache.yml up -d
GET _ingest/pipeline
GET _template
Grok pattern for Apache - beats send raw data to ES; pipeline processes doc
cp data/apache_logs-small labs/beats/data
docker logs elkstack_filebeat_1 -f
ls labs/beats/data
File still there, Filebeat keeps an open read
Kibana
docker-compose -f labs\beats\filebeat-apache.yml -f labs\beats\filebeat-simplecsv.yml down
Ignore errors
rm -fo labs/beats/data/
docker-compose -f labs\beats\logstash.yml up -d
docker-compose -f labs\beats\logstash.yml logs -f
Connection to backoff(async(tcp://logstash:5044)) established
filebeat-7.10.2-apache
and fb-ls-simplecsv
cp data/apache_logs-2021* labs/beats/data/
cp data/simple.csv labs/beats/data/
kibana
use the filebeat-7.10.2-apache
index for the apache dashboard