Tell me how to set up a collection of Syslog logs from the glands on Elasticsearch + Kibana + Logstash(ELK).
Pieces Zyxel Zywall, Eltex Tau and CentOS server.
I set up the server for this article https://www.digitalocean.com/community/tutorials/h...
Logging with Zyxel goes on port 514.
The output of the logs of this format
02-17-2015 15:29:07 Local1.Info 192.168.91.254 Feb 17 15:29:09 zywall- zw1100 cef: 0 | zyxel | zywall 1100 || 0 | ike | 4 | src=xxx.xxx.xxx.xxxdst=xx.xx.xx.xxspt=500 dpt=500 msg=Recv:[HASH][NOTIFY: R_U_THERE_ACK ]
But the logs never come.Looked at the logs, everything seems to be fine.I don’t know where to dig further.
Disconnected FirewallD and Selinux set SELINUX=permissive.
I successfully login to the web interface.
Actually the configs themselves for logstash
By the way, in htop, I do not see the logstash process, so it should be?