robcowart / elastiflow

Network flow analytics (Netflow, sFlow and IPFIX) with the Elastic Stack
Other
2.49k stars 596 forks source link

Elastiflow : Not generating enough data in Elastic #707

Closed gauravubnare closed 3 years ago

gauravubnare commented 3 years ago

Hello,

Screenshot from 2021-04-15 11-28-19

Server Config. OS - Centos 7 Kernel - 3.10.0-1160.24.1.el7.x86_64 8 CPU 16 GB RAM 100+ GB Storage SELinux - disabled Logstash JVM - 8 GB

Also, In parallel to this on the same server we are running heartbeat, metricbeat and logstash snmp. but the same setup we have for other servers as well the only difference is of OS. In all other server we are using ubuntu. In this VM we are using centos7

In the logs we see this. we have followed the Installation guide posted on github. UDP listener started {:address=>"0.0.0.0:2055", :receive_buffer_bytes=>"33554432", :queue_size=>"4096"}

Pls help us on this.

Thanks!!

gauravubnare commented 3 years ago

Forgot to mention logstash version - logstash-7.9.0-1.noarch Elastic version - 7.10.1 Java Version

/usr/bin/java -version openjdk version "11.0.10" 2021-01-19 LTS OpenJDK Runtime Environment 18.9 (build 11.0.10+9-LTS) OpenJDK 64-Bit Server VM 18.9 (build 11.0.10+9-LTS, mixed mode, sharing)

robcowart commented 3 years ago

I would need to see the full logs from Logstash starting. I also need to see the file /etc/systemd/system/logstaash.service.