How to Install ELK Stack (Elasticsearch, Logstash and Kibana) on CentOS 7 / RHEL 7

Pradeep Kumar

I am a huge fan of open source and love to share How To's tutorials on Linux, Cloud and DevOps. I have been working as Linux Consultant, Cloud & DevOps Engineer since 2010

You may also like...

6 Responses

  1. shashank says:

    Nice article. Thanks. But we are facing one problem. The filebeat is not sending the logs to Logstash as logs changes at client . We need to restart the filebeat every time on client to send the logs. Is there any setting which defines auto sending of Logs or time-interval at which file beat sends the logs ?

    • Hi Shashank,

      You need to edit your client’s filebeat.yml file. Update the entries whatever we discuss in document and also make sure you comment out the following lines in filebeat.yml

      ### Elasticsearch as output
      #elasticsearch:

      #hosts: [“localhost:9200”]

      Restart the filebeat service on client and then restart logstash service on elk server. To perform testing logout from your client and then re-login and verify the logs on Kibana, Logs should be updated for your client.

  2. Daniel Hernandez says:

    hi Pradeep,

    I found an error during creation SSL certificate with 365 days validity. please give a check I looked it for in webpages but I dont find any fix.

    thanks in advnace

    openssl req -x509 -days 365 -batch -nodes -newkey rsa:2048 -keyout logstash-forwarder.key -out logstash_frwrd.crt
    Error Loading extension section v3_ca
    139742382225312:error:2207507C:X509 V3 routines:v2i_GENERAL_NAME_ex:missing value:v3_alt.c:537:
    139742382225312:error:22098080:X509 V3 routines:X509V3_EXT_nconf:error in extension:v3_conf.c:93:name=subjectAltName, val ue=10.1.1.41

    • chiefwilson says:

      Daniel,

      I’m pretty sure you entered a typo. Recheck the openssl conf file and ensure you’ve entered the following under the [v3_ca]:

      subjectAltName = IP: 10.1.1.41

  3. suresh says:

    Unable to fetch mapping. Do you have indices matching the pattern…I couldn’t create index pattern bcoz it shows this area as transparent in the start page

  4. savi says:

    yum install filebeat
    file contain pasring errors:file:///etc/yum.repos.d/filebeat.respo

Leave a Reply

Your email address will not be published. Required fields are marked *