Closed sdresen closed 3 years ago
@sdresen - Thanks for providing a detailed request.
Let's break this down into two segments:
observer.name
02-types.conf
file along with observer.product
and observer.serial_number
07-interfaces.conf
where you can define your network interfaces and aliases (referenced herepfelk-settings
and pfelk-mappings-ecs
templates are installed within Management>>Index Management>>Component Templates?Thank you for the quick response. I think deleting the indices did much of the trick to get the reporting working. I updated the observer.product and observer.serial_number fields. I did confirm that the pfelk-settings and pfelk-mappings-ecs are present in the Component Templates section (screen shot attached).
The Firewall and DHCP visualizations appear to be working correctly. I'm still seeing "obj is undefined" for the Unbound dashboard.
Lastly, can you provide a bit more direction on the original.log message you'd like. Not clear what I should send.
@sdresen - Whew...glad that resolved most of the issue. I suspect that you had logs being sent prior to configuring (adding) the various templates if so the remedy is to purge the current indices which appears to have resolved your issue.
As for the unbound portion, are you running unbound (I assume you are)? However, the initial screenshot did not depict any indices (i.e. no received logs).
The unbound issue may be that there's no DNS traffic hitting the pfSense unbound server. Unbound is active and running but I use PiHole's internally. So, could be simply that there's no traffic resolution hitting it.
That would be it! So looks like your up/running (e.g. everything good?).
Yes, all good, many thanks!
Resolved
Describe the bug Fresh install using Docker. Visualizations in dashboards showing errors and not presenting data.
To Reproduce Steps to reproduce the behavior:
Screenshots If applicable, add screenshots to help explain your problem.
Operating System (please complete the following information): Linux 5.4.0-58-generic x86_64 NAME="Ubuntu" VERSION="20.04.1 LTS (Focal Fossa)" ID=ubuntu ID_LIKE=debian PRETTY_NAME="Ubuntu 20.04.1 LTS" VERSION_ID="20.04" HOME_URL="https://www.ubuntu.com/" SUPPORT_URL="https://help.ubuntu.com/" BUG_REPORT_URL="https://bugs.launchpad.net/ubuntu/" PRIVACY_POLICY_URL="https://www.ubuntu.com/legal/terms-and-policies/privacy-policy" VERSION_CODENAME=focal UBUNTU_CODENAME=focal
Docker version 20.10.1, build 831ebea docker-compose version 1.25.0, build unknown
Elasticsearch, Logstash, Kibana (please complete the following information):
Version of ELK: ELK_VERSION=7.10.0
**Service logs es01.log es02.log es03.log kibana.log logstash.log
Additional context Screenshots
Last Note of Interest I am using pfSense and yet the Observer.Name field shows "OPNSense" in the Discover view where you see the specific data enrichment fields (Log Enrichment screenshot).