ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    SysLog Forwarding for XenServer

    IT Discussion
    rsyslog xenserver logging kibana elk elasticsearch
    10
    110
    23.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller
      last edited by

      Yeah. That way you know it is working before you make other changes.

      1 Reply Last reply Reply Quote 0
      • DustinB3403D
        DustinB3403
        last edited by

        So for everyone looking to do this,

        Start here
        Then here

        And then (and @scottalanmiller I'm asking for confirmation) perform what I posted in the OP.

        Correct?

        1 Reply Last reply Reply Quote 1
        • DustinB3403D
          DustinB3403
          last edited by

          So on a brand new installation of Centos7 after completing Elk on Cent and then progressing to https://mangolassi.it/topic/8308/configuring-logstash-and-filebeat-to-send-to-elk-logging-system

          I get this...

          0_1470952896859_putty_2016-08-11_18-01-31.png

          1 Reply Last reply Reply Quote 0
          • DustinB3403D
            DustinB3403
            last edited by

            Same thing with sudo

            1 Reply Last reply Reply Quote 0
            • DustinB3403D
              DustinB3403
              last edited by

              What is missing from the second script is

              curl -L -O https://download.elastic.co/beats/filebeat/filebeat-1.2.3-x86_64.rpm
              
              sudo rpm -vi filebeat-1.2.3-x86_64.rpm
              
              1 Reply Last reply Reply Quote 2
              • DustinB3403D
                DustinB3403
                last edited by

                So I'm still stumped here....

                1 Reply Last reply Reply Quote 0
                • DustinB3403D
                  DustinB3403
                  last edited by DustinB3403

                  Hrm, so I have a clean installation and when I go to the Elk/Logstash Web url I get a login prompt...

                  But I haven't the slightest idea of what the username password is.

                  Trying "kibana" and "changeme" results in the prompt asking for credentials again...

                  1 Reply Last reply Reply Quote 0
                  • DustinB3403D
                    DustinB3403
                    last edited by

                    And I'm in.

                    Now to setup XenServer to send stuff to Kibana.

                    1 Reply Last reply Reply Quote 0
                    • DustinB3403D
                      DustinB3403
                      last edited by

                      OK So I'm in, and apparently logs are getting sent to this VM.... now how do I see them... lol....

                      So much to learn...

                      StrongBadS 1 Reply Last reply Reply Quote 0
                      • StrongBadS
                        StrongBad @DustinB3403
                        last edited by

                        @DustinB3403 said in SysLog Forwarding for XenServer:

                        OK So I'm in, and apparently logs are getting sent to this VM.... now how do I see them... lol....

                        So much to learn...

                        Have you looked in Kibana yet?

                        DustinB3403D 1 Reply Last reply Reply Quote 0
                        • DustinB3403D
                          DustinB3403 @StrongBad
                          last edited by

                          @StrongBad Yes, and nothing is showing up.

                          So there might be something I messed up while configuring it, or there just isn't anything set to show yet.

                          1 Reply Last reply Reply Quote 0
                          • StrongBadS
                            StrongBad
                            last edited by

                            They show up quickly. We're the logs pretty regular before the change?

                            DustinB3403D 1 Reply Last reply Reply Quote 1
                            • StrongBadS
                              StrongBad
                              last edited by

                              LMFAO. Regular. Logs.

                              1 Reply Last reply Reply Quote 1
                              • DustinB3403D
                                DustinB3403 @StrongBad
                                last edited by

                                @StrongBad said in SysLog Forwarding for XenServer:

                                They show up quickly. We're the logs pretty regular before the change?

                                With just a basic syslog server setup and forwarding enabled when I viewed /var/log/messages it was blowing by

                                1 Reply Last reply Reply Quote 0
                                • DustinB3403D
                                  DustinB3403
                                  last edited by

                                  0_1471021829374_chrome_2016-08-12_13-10-17.png

                                  1 Reply Last reply Reply Quote 0
                                  • DustinB3403D
                                    DustinB3403
                                    last edited by

                                    0_1471021953539_chrome_2016-08-12_13-12-17.png

                                    1 Reply Last reply Reply Quote 0
                                    • DustinB3403D
                                      DustinB3403
                                      last edited by

                                      I still have a few compressed logs (things that aren't marked to be forward to Elk/Kibana)

                                      1 Reply Last reply Reply Quote 0
                                      • DustinB3403D
                                        DustinB3403
                                        last edited by

                                        0_1471022072411_XenCenterMain_2016-08-12_13-14-25.png

                                        Obviously I'll need to change the syslog file to make sure those are only sent off host.

                                        But why aren't they appearing in Elk/Kibana...

                                        1 Reply Last reply Reply Quote 0
                                        • DustinB3403D
                                          DustinB3403
                                          last edited by

                                          Everything here seems happy.

                                          0_1471022151987_chrome_2016-08-12_13-15-37.png

                                          1 Reply Last reply Reply Quote 1
                                          • DustinB3403D
                                            DustinB3403
                                            last edited by

                                            I still don't know why the logging isn't showing up in Kibana. . .

                                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 6
                                            • 3 / 6
                                            • First post
                                              Last post