Difference between revisions of "ELK"
Jump to navigation
Jump to search
Line 20: | Line 20: | ||
<pre> |
<pre> |
||
curl "http://localhost:9200/_search q=type:syslog&pretty=true" |
curl "http://localhost:9200/_search q=type:syslog&pretty=true" |
||
+ | </pre> |
||
+ | |||
+ | Add entry in syslog |
||
+ | <pre> |
||
+ | logger -i "Test message" |
||
</pre> |
</pre> |
Revision as of 10:07, 24 May 2016
ELK = Elastic Search + Logstash + Kibana
https://www.logstashbook.com/TheLogstashBook_sample.pdf
Check the Logstash configuration
/opt/logstash/bin/logstash agent -f logstash.conf --configtest
Check if Elasticsearch is running
curl http://localhost:9200/_status?pretty=true
Check to see if Logstash is getting events to Elasticsearch
curl "http://localhost:9200/_search q=type:syslog&pretty=true"
Add entry in syslog
logger -i "Test message"