Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Kibana+Elasticsearch+Logstash [ELK] v5+|pfSense v2.3+|Ubuntu 16.04+

    Scheduled Pinned Locked Moved General pfSense Questions
    6 Posts 4 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V Offline
      vitormazuco
      last edited by

      Hi people, I just follow this article

      http://pfelk.3ilson.com/2016/11/kibanaelasticsearchlogstash-plugin-x.html

      But I am almost completed however when I try to import the visualizations.json from the file I get an error of "Saved Objects: Could not locate that index-pattern-field (id: dest_port.keyword)"

      running pfsense 2.3.2-RELEASE-p1 and Ubuntu 16.04

      Anybody here have already use this software?

      1 Reply Last reply Reply Quote 0
      • A Offline
        AR15USR
        last edited by

        I remember reading somewhere you had to import the 3 files in the correct order. I think it is: searches then visualizations then dashboard. Not sure though..


        2.6.0-RELEASE

        1 Reply Last reply Reply Quote 0
        • S Offline
          Starfleet
          last edited by

          No matter how I try to import, I am not getting past this error.

          1 Reply Last reply Reply Quote 0
          • S Offline
            Starfleet
            last edited by

            At a guess, something in the latest versions of ELK is no longer supported by the initial configuration.

            1 Reply Last reply Reply Quote 0
            • S Offline
              Starfleet
              last edited by

              Ok, so it looks like ELK changed the way some mappings worked in their latest upgrade. This visualization file will get everything working but the geoip related items. Rename as json and import and it should work.

              If you are interested in the changes, use a diff program to compare the two files.

              (in short, the names of items needed to be changed to name.raw instead of name)

              https://github.com/elastic/elasticsearch/issues/15267

              (Note, you need to be logged in to see the attached file. Sorry, didn't realize that until I looked at this while logged out.)

              Visualizationsrevised.txt

              1 Reply Last reply Reply Quote 0
              • B Offline
                BrunoCAVILLE
                last edited by

                Thanks a lot! I just have one problem, it doesn't show me the maps as you can see on the pic.

                ![Capture d’écran 2017-05-05 à 15.18.39.png](/public/imported_attachments/1/Capture d’écran 2017-05-05 à 15.18.39.png)
                ![Capture d’écran 2017-05-05 à 15.18.39.png_thumb](/public/imported_attachments/1/Capture d’écran 2017-05-05 à 15.18.39.png_thumb)

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.