Describe the bug
When following the documentation, the logstash container is unable to reach the es01 instance because the output host is set to http://localhost:9200 rather than http://es01:9200.
Additionally, the MaxMind documentation states to update line 18 to be DatabaseDirectory /usr/share/GeoIP/, but the corresponding path in the docker-compose.yml file for the logstash container is /usr/share/GeoIP/:/usr/share/logstash/GeoIP/ which results in being unable to load the files.
To Reproduce
Steps to reproduce the behavior:
follow the docker installation guide step-by-step on a new Ubuntu 20.04 installation.
Screenshots
If applicable, add screenshots to help explain your problem.
Operating System (please complete the following information):
OS (printf "$(uname -srm)\n$(cat /etc/os-release)\n"):
Version of Docker (docker -v): Docker version 20.10.2, build 2291f61
Version of Docker-Compose (docker-compose -v): docker-compose version 1.25.0, build unknown
Elasticsearch, Logstash, Kibana (please complete the following information):
Version of ELK (cat /docker-pfelk/.env)
**Service logs
docker-compose logs pfelk01
docker-compose logs pfelk02
docker-compose logs pfelk03
docker-compose logs logstash
docker-compose logs kibana
Additional context
I'm going to add a PR shortly, so I'm skipping the service logs since I've already fixed the bug locally and it seems fairly obvious. If you'd like me to go back and re-do this, I'm happy to.
Describe the bug When following the documentation, the logstash container is unable to reach the
es01
instance because the output host is set tohttp://localhost:9200
rather thanhttp://es01:9200
.Additionally, the MaxMind documentation states to update line 18 to be
DatabaseDirectory /usr/share/GeoIP/
, but the corresponding path in thedocker-compose.yml
file for the logstash container is/usr/share/GeoIP/:/usr/share/logstash/GeoIP/
which results in being unable to load the files.To Reproduce Steps to reproduce the behavior:
Screenshots If applicable, add screenshots to help explain your problem.
Operating System (please complete the following information):
printf "$(uname -srm)\n$(cat /etc/os-release)\n"
):docker -v
):Docker version 20.10.2, build 2291f61
docker-compose -v
):docker-compose version 1.25.0, build unknown
Elasticsearch, Logstash, Kibana (please complete the following information):
Version of ELK (
cat /docker-pfelk/.env
)**Service logs
docker-compose logs pfelk01
docker-compose logs pfelk02
docker-compose logs pfelk03
docker-compose logs logstash
docker-compose logs kibana
Additional context I'm going to add a PR shortly, so I'm skipping the service logs since I've already fixed the bug locally and it seems fairly obvious. If you'd like me to go back and re-do this, I'm happy to.