Hi ,
Please find the attachment of config files found in /usr/local/nagioslogserver/logstash/etc/conf.d ,source conf file and details of /var/log/httpd/access_log and /var/log/httpd/error_log
And also attached logstash.log and elasticsearch . Please check the logs as well .
here are details of access_log and error_log while adding the source
[root@SESKLNGLSIPD01 /]# tail -f /var/log/httpd/access_log
172.18.213.170 - - [13/Jul/2017:08:44:36 -0400] "GET /nagioslogserver/api/backend/logstash-2017.07.13/_aliases?ignore_missing=true HTTP/1.1" 200 38 "
http://sesklnglsipd01/nagioslogserver/dashboard" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.115 Safari/537.36"
172.18.213.170 - - [13/Jul/2017:08:44:36 -0400] "GET /nagioslogserver/api/backend/logstash-2017.07.13/_mapping HTTP/1.1" 200 52200 "
http://sesklnglsipd01/nagioslogserver/dashboard" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.115 Safari/537.36"
172.18.213.170 - - [13/Jul/2017:08:44:36 -0400] "POST /nagioslogserver/api/backend/logstash-2017.07.13/_search HTTP/1.1" 200 124 "
http://sesklnglsipd01/nagioslogserver/dashboard" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.115 Safari/537.36"
172.18.213.170 - - [13/Jul/2017:08:44:36 -0400] "POST /nagioslogserver/api/backend/logstash-2017.07.13/_search?search_type=count HTTP/1.1" 200 179 "
http://sesklnglsipd01/nagioslogserver/dashboard" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.115 Safari/537.36"
172.18.213.170 - - [13/Jul/2017:08:44:39 -0400] "GET /nagioslogserver/api/backend/logstash-2017.07.13/_aliases?ignore_missing=true HTTP/1.1" 200 38 "
http://sesklnglsipd01/nagioslogserver/dashboard" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.115 Safari/537.36"
172.18.213.170 - - [13/Jul/2017:08:44:40 -0400] "GET /nagioslogserver/api/backend/logstash-2017.07.13/_mapping HTTP/1.1" 200 52200 "
http://sesklnglsipd01/nagioslogserver/dashboard" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.115 Safari/537.36"
172.18.213.170 - - [13/Jul/2017:08:44:40 -0400] "POST /nagioslogserver/api/backend/logstash-2017.07.13/_search HTTP/1.1" 200 124 "
http://sesklnglsipd01/nagioslogserver/dashboard" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.115 Safari/537.36"
172.18.213.170 - - [13/Jul/2017:08:44:40 -0400] "POST /nagioslogserver/api/backend/logstash-2017.07.13/_search?search_type=count HTTP/1.1" 200 180 "
http://sesklnglsipd01/nagioslogserver/dashboard" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.115 Safari/537.36"
172.18.213.170 - - [13/Jul/2017:08:44:41 -0400] "POST /nagioslogserver/api/system/status HTTP/1.1" 200 82 "
http://sesklnglsipd01/nagioslogserver/dashboard" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.115 Safari/537.36"
172.18.213.170 - - [13/Jul/2017:08:44:41 -0400] "POST /nagioslogserver/api/system/status HTTP/1.1" 200 87 "
http://sesklnglsipd01/nagioslogserver/dashboard" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.115 Safari/537.36"
^C
[root@SESKLNGLSIPD01 /]# ^C
[root@SESKLNGLSIPD01 /]# tail -f /var/log/httpd/error_log
[Wed Jul 12 13:00:25 2017] [notice] suEXEC mechanism enabled (wrapper: /usr/sbin/suexec)
[Wed Jul 12 13:00:25 2017] [notice] Digest: generating secret for digest authentication ...
[Wed Jul 12 13:00:25 2017] [notice] Digest: done
[Wed Jul 12 13:00:25 2017] [notice] Apache/2.2.15 (Unix) DAV/2 PHP/5.3.3 configured -- resuming normal operations
curl: (7) Failed to connect to 2600

:f03c:91ff:fe18:849c: Network is unreachable
curl: (7) Failed to connect to 2600

:f03c:91ff:fe18:849c: Network is unreachable
curl: (7) Failed to connect to 2600

:f03c:91ff:fe18:849c: Network is unreachable
I have just gone through some of the posts in Nagios Support . So I am forwarding you the details of the command .
/usr/local/nagioslogserver/logstash/bin/logstash -f /usr/local/nagioslogserver/logstash/etc/conf.d
[root@SESKLNGLSIPD01 /]# /usr/local/nagioslogserver/logstash/bin/logstash -f /usr/local/nagioslogserver/logstash/etc/conf.d
syslog listener died {:protocol=>:tcp, :address=>"0.0.0.0:5544", :exception=>#<Errno::EADDRINUSE: Address already in use - bind - Address already in use>, :backtrace=>["org/jruby/ext/socket/RubyTCPServer.java:118:in `initialize'", "org/jruby/RubyIO.java:853:in `new'", "/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-syslog-0.1.6/lib/logstash/inputs/syslog.rb:152:in `tcp_listener'", "/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-syslog-0.1.6/lib/logstash/inputs/syslog.rb:117:in `server'", "/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-syslog-0.1.6/lib/logstash/inputs/syslog.rb:101:in `run'"], :level=>:warn}
syslog listener died {:protocol=>:udp, :address=>"0.0.0.0:5544", :exception=>#<SocketError: bind: name or service not known>, :backtrace=>["org/jruby/ext/socket/RubyUDPSocket.java:160:in `bind'", "/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-syslog-0.1.6/lib/logstash/inputs/syslog.rb:135:in `udp_listener'", "/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-syslog-0.1.6/lib/logstash/inputs/syslog.rb:117:in `server'", "/usr/local/nagioslogserver/logstash/vendor/bundle/jruby/1.9/gems/logstash-input-syslog-0.1.6/lib/logstash/inputs/syslog.rb:97:in `run'"], :level=>:warn}
Could not start TCP server: Address in use {:host=>"0.0.0.0", :port=>3515, :level=>:error}
The error reported is:
Address already in use - bind - Address already in use
You do not have the required permissions to view the files attached to this post.