NLS not accepting messages
Posted: Wed Mar 04, 2015 3:33 pm
I have a working ELK test server that I have been running for a few weeks. I'm now testing my first NLS cluster and ran into a snag. One of my nodes is the same IP of my ELK server that I shutdown. I chose to do it this way that so I could be sure the firewall rules,etc would not be an issue. However the only messages I am seeing come through are for NLS itself and they all have the same host.
Message -> " nagios : TTY=unknown ; PWD=/var/www/html/nagioslogserver/www ; USER=root ; COMMAND=/etc/init.d/logstash status"
Host -> 0:0:0:0:0:0:0:1
I copied my inputs from my ELK config and changed LS to run as root so it would listen on TCP/UDP 514 but still no luck. Most of my traffic come in on TCP5000 and 514.
Is it possible that NLS is only working on localhost or an IPV6 address. It does look like IPV6 is disabled but I'm not sure.
Please advise.
thank you.
Message -> " nagios : TTY=unknown ; PWD=/var/www/html/nagioslogserver/www ; USER=root ; COMMAND=/etc/init.d/logstash status"
Host -> 0:0:0:0:0:0:0:1
I copied my inputs from my ELK config and changed LS to run as root so it would listen on TCP/UDP 514 but still no luck. Most of my traffic come in on TCP5000 and 514.
Is it possible that NLS is only working on localhost or an IPV6 address. It does look like IPV6 is disabled but I'm not sure.
Please advise.
thank you.