and added a log source
###########################################################
Code: Select all
[root@host_name ~]# curl -s -O http://dev-tailor2/nagioslogserver/scripts/setup-linux.sh
[root@Host_name ~]# bash setup-linux.sh -s dev-tailor2 -p 5544
Your system $PATH does not include /sbin and /usr/sbin. This could be the result of installing GNOME rather than creating a clean system.
Adding /sbin and /usr/sbin to $PATH.
Detected rsyslog 7.4.7
Detected rsyslog work directory /var/lib/rsyslog
Destination Log Server: dev-tailor2:5544
Creating /etc/rsyslog.d/99-nagioslogserver.conf...
rsyslog configuration check passed.
Restarting rsyslog service with 'service'...
Redirecting to /bin/systemctl restart rsyslog.service
Okay.
rsyslog is running with the new configuration.
Visit your Nagios Log Server dashboard to verify that logs are being received.But nothing on the dashboard
logstash is running properly
###########################################################################
Code: Select all
Logstash Daemonlogstash.service - LSB: Logstash
Loaded: loaded (/etc/rc.d/init.d/logstash)
Active: active (exited) since Fri 2016-08-12 10:18:13 WST; 9min ago
Process: 9098 ExecStop=/etc/rc.d/init.d/logstash stop (code=exited, status=0/SUCCESS)
Process: 9108 ExecStart=/etc/rc.d/init.d/logstash start (code=exited, status=0/SUCCESS)
Aug 12 10:18:24 XXXXXXXXXXXX logstash[9108]: start_inputs at /usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.1-java/lib/logstash/pipeline.rb:147
Aug 12 10:18:24 XXXXXXXXXXX logstash[9108]: synchronize at org/jruby/ext/thread/Mutex.java:149
Aug 12 10:18:24 XXXXXXXXXXXXXX logstash[9108]: run at /usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.1-java/lib/logstash/pipeline.rb:80
Aug 12 10:18:24 XXXXXXXXXXXXXXXXXXXX logstash[9108]: run at /usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.1-java/lib/logstash/pipeline.rb:80
Aug 12 10:18:24 XXXXXXXXXXXXXXXXX logstash[9108]: execute at /usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.1-java/lib/logstash/agent.rb:150
Aug 12 10:18:24 XXXXXXXXXXXXXXXXXXXXXXXX logstash[9108]: call at org/jruby/RubyProc.java:271
Aug 12 10:18:24 XXXXXXXXXXXXXXXX logstash[9108]: run at /usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.1-java/lib/logstash/runner.rb:87
Aug 12 10:18:24 XXXXXXXXXXXXXXX logstash[9108]: call at org/jruby/RubyProc.java:271
Aug 12 10:18:24 XXXXXXXXXXXXXXXXXXXXXXXXX logstash[9108]: run at /usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.1-java/lib/logstash/runner.rb:92
Aug 12 10:18:24 XXXXXXXXXXXXXXXXX runuser[9114]: pam_unix(runuser:session): session closed for user nagiosand reciving logs from log source
Code: Select all
# tcpdump src host log_source_ip and tcp dst port 5544 and dst host nagioslogserver_IP
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes
10:19:16.962508 IP XXXXXXXXXXXXXXXX .37905 > XXXXXXXXXXXXXXXX .5544: Flags [S], seq 2102465374, win 14600, options [mss 1460,sackOK,TS val 407808648 ecr 0,nop,wscale 7], length 0
10:19:46.998323 IP XXXXXXXXXXXXXXXX .37978 > XXXXXXXXXXXXXXXX .5544: Flags [S], seq 3196620400, win 14600, options [mss 1460,sackOK,TS val 407838684 ecr 0,nop,wscale 7], length 0
10:20:17.031352 IP XXXXXXXXXXXXXXXX .38051 > XXXXXXXXXXXXXXXX .5544: Flags [S], seq 3355995753, win 14600, options [mss 1460,sackOK,TS val 407868717 ecr 0,nop,wscale 7], length 0
10:20:47.068592 IP XXXXXXXXXXXXXXXX .38124 > XXXXXXXXXXXXXXXX .5544: Flags [S], seq 1053464637, win 14600, options [mss 1460,sackOK,TS val 407898753 ecr 0,nop,wscale 7], length 0
10:21:17.104351 IP XXXXXXXXXXXXXXXX .38197 > XXXXXXXXXXXXXXXX .5544: Flags [S], seq 3442125058, win 14600, options [mss 1460,sackOK,TS val 407928790 ecr 0,nop,wscale 7], length 0
10:21:47.138719 IP XXXXXXXXXXXXXXXX .38269 > XXXXXXXXXXXXXXXX .5544: Flags [S], seq 787019552, win 14600, options [mss 1460,sackOK,TS val 407958826 ecr 0,nop,wscale 7], length 0
10:22:17.148512 IP XXXXXXXXXXXXXXXX .38339 > XXXXXXXXXXXXXXXX .5544: Flags [S], seq 2978900797, win 14600, options [mss 1460,sackOK,TS val 407988836 ecr 0,nop,wscale 7], length 0
10:22:47.178124 IP XXXXXXXXXXXXXXXX .38411 > XXXXXXXXXXXXXXXX .5544: Flags [S], seq 2829264381, win 14600, options [mss 1460,sackOK,TS val 408018866 ecr 0,nop,wscale 7], length 0
10:23:17.213777 IP XXXXXXXXXXXXXXXX .38484 > XXXXXXXXXXXXXXXX .5544: Flags [S], seq 2114725888, win 14600, options [mss 1460,sackOK,TS val 408048902 ecr 0,nop,wscale 7], length 0
10:23:47.250438 IP XXXXXXXXXXXXXXXX .38557 > XXXXXXXXXXXXXXXX .5544: Flags [S], seq 3844739351, win 14600, options [mss 1460,sackOK,TS val 408078939 ecr 0,nop,wscale 7], length 0
10:24:17.288118 IP XXXXXXXXXXXXXXXX .38630 > XXXXXXXXXXXXXXXX .5544: Flags [S], seq 2147035330, win 14600, options [mss 1460,sackOK,TS val 408108977 ecr 0,nop,wscale 7], length 0
10:24:47.325623 IP XXXXXXXXXXXXXXXX .38704 > XXXXXXXXXXXXXXXX .5544: Flags [S], seq 896153796, win 14600, options [mss 1460,sackOK,TS val 408139014 ecr 0,nop,wscale 7], length 0
10:25:17.359677 IP XXXXXXXXXXXXXXXX .38776 > XXXXXXXXXXXXXXXX .5544: Flags [S], seq 3569642898, win 14600, options [mss 1460,sackOK,TS val 408169049 ecr 0,nop,wscale 7], length 0
10:25:47.395299 IP XXXXXXXXXXXXXXXX .38849 > XXXXXXXXXXXXXXXX .5544: Flags [S], seq 2910915721, win 14600, options [mss 1460,sackOK,TS val 408199085 ecr 0,nop,wscale 7], length 0
10:26:17.431332 IP XXXXXXXXXXXXXXXX .38921 > XXXXXXXXXXXXXXXX .5544: Flags [S], seq 2016469944, win 14600, options [mss 1460,sackOK,TS val 408229121 ecr 0,nop,wscale 7], length 0
10:26:47.459425 IP XXXXXXXXXXXXXXXX .38994 > XXXXXXXXXXXXXXXX .5544: Flags [S], seq 2888103235, win 14600, options [mss 1460,sackOK,TS val 408259150 ecr 0,nop,wscale 7], length 0
10:27:17.494092 IP XXXXXXXXXXXXXXXX .39067 > XXXXXXXXXXXXXXXX .5544: Flags [S], seq 2209121603, win 14600, options [mss 1460,sackOK,TS val 408289185 ecr 0,nop,wscale 7], length 0What could be reason for this ?