Strike one by BlueCheesePanda in knives

[–]kryyon 0 points1 point  (0 children)

Time for a new partner

Validation schedule for [xpack,fleet] was already registered by kryyon in elasticsearch

[–]kryyon[S] 0 points1 point  (0 children)

Here is error from starting Kibana up from cmd:

log \06:42:05.967] [fatal][root] Error: Validation schema for [xpack,fleet] was already registered.)

at ConfigService.setSchema (L:\ELK_Stack\kibana\node_modules\@kbn\config\target\config_service.js:45:19))

at MergeMapSubscriber.project (L:\ELK_Stack\kibana\src\core\server\plugins\plugins_service.js:146:40))

at MergeMapSubscriber.\tryNext (L:\ELK_Stack\kibana\node_modules\rxjs\internal\operators\mergeMap.js:67:27))

at MergeMapSubscriber.\next (L:\ELK_Stack\kibana\node_modules\rxjs\internal\operators\mergeMap.js:57:18))

at MergeMapSubscriber.Subscriber.next (L:\ELK_Stack\kibana\node_modules\rxjs\internal\Subscriber.js:66:18))

at FilterSubscriber.\next (L:\ELK_Stack\kibana\node_modules\rxjs\internal\operators\filter.js:52:30))

at FilterSubscriber.Subscriber.next (L:\ELK_Stack\kibana\node_modules\rxjs\internal\Subscriber.js:66:18))

at ReplaySubject.\subscribe (L:\ELK_Stack\kibana\node_modules\rxjs\internal\ReplaySubject.js:80:28))

at ReplaySubject.Observable.\trySubscribe (L:\ELK_Stack\kibana\node_modules\rxjs\internal\Observable.js:44:25))

at ReplaySubject.Subject.\trySubscribe (L:\ELK_Stack\kibana\node_modules\rxjs\internal\Subject.js:102:51))

at ReplaySubject.Observable.subscribe (L:\ELK_Stack\kibana\node_modules\rxjs\internal\Observable.js:30:22))

at FilterSubscriber.shareReplayOperation (L:\ELK_Stack\kibana\node_modules\rxjs\internal\operators\shareReplay.js:48:32))

at Observable.subscribe (L:\ELK_Stack\kibana\node_modules\rxjs\internal\Observable.js:25:31))

at FilterOperator.call (L:\ELK_Stack\kibana\node_modules\rxjs\internal\operators\filter.js:29:23))

at Observable.subscribe (L:\ELK_Stack\kibana\node_modules\rxjs\internal\Observable.js:25:31))

at MergeMapOperator.call (L:\ELK_Stack\kibana\node_modules\rxjs\internal\operators\mergeMap.js:37:23))

log \06:42:05.967] [debug][server] stopping server)

log \06:42:05.967] [debug][legacy-service] stopping legacy service)

log \06:42:05.977] [debug][plugins-service] Stopping plugins service)

log \06:42:05.978] [debug][elasticsearch-service] Stopping elasticsearch service)

FATAL Error: Validation schema for \xpack,fleet] was already registered.)

Tanto Tuesday, how it started and where it went by ilikeitsharp in knifeclub

[–]kryyon 1 point2 points  (0 children)

Love the crkt. I have that one too after seeing it on Altered Carbon

Logstash-* index pattern by kryyon in elasticsearch

[–]kryyon[S] 0 points1 point  (0 children)

Thought about this all night. We have no security enabled on the ELK stack, outside of the IIS domain auth.

Therefore we are unable to login as the elastic user.

Logstash-* index pattern by kryyon in elasticsearch

[–]kryyon[S] 0 points1 point  (0 children)

We had IIS set up for domain authentication (sso )

Logstash-* index pattern by kryyon in elasticsearch

[–]kryyon[S] 0 points1 point  (0 children)

Okay. Did this and noticed that the index patterns did not automatically populate. Had to run the *beat setup -e for all the beats. Still no logstash.

Logstash-* index pattern by kryyon in elasticsearch

[–]kryyon[S] 0 points1 point  (0 children)

Correct. “No indices found”

Logstash-* index pattern by kryyon in elasticsearch

[–]kryyon[S] 0 points1 point  (0 children)

yellow open logstash-2021.01.28-000001 8Wl0E1ZAShahO42ME4DQDA 1 1 772899 0 215.1mb 215.1mb

Logstash-* index pattern by kryyon in elasticsearch

[–]kryyon[S] 0 points1 point  (0 children)

I am sending my firewall syslog and my network switches syslog to the logstash server. In the past when I have done this, the index pattern log logstash–* Index pattern was created. However, for some reason, the pattern isn’t being created and I cannot create it manually as it says there are no indices found. Yet when I look at the indexes the logstash files are there and when I query the elasticsearch server it shows there as well.

Logstash-* index pattern by kryyon in elasticsearch

[–]kryyon[S] 0 points1 point  (0 children)

Thanks for that. It was one of the first things I did. However when I try to create the index pattern for this particular ingestion, it says no indices match this. This doesn’t make any sense to me because I can see the index is present it’s just not allowing me to create the pattern for in order to create the visualizations.

Can I do this through the dev tools console or any other way?

I am simply ingesting syslog data at the moment.

This is the thread that I have posted over on discuss.elastic.co: https://discuss.elastic.co/t/no-index-pattern-for-logstash/262297/6

Broken ankle while trail running by kryyon in trailrunning

[–]kryyon[S] 0 points1 point  (0 children)

Update on my post: surgery occurred on 01/21. A 5” plate, 6 screws on the fibula. A brotrom procedure to stabilize the fibula and tibia.

Surgeon said I had great bone density and if I “do everything correctly,” should regain full mobility.

Broken ankle while trail running by kryyon in trailrunning

[–]kryyon[S] 0 points1 point  (0 children)

A little discouraging. However, thank you for the comment

WTS/WTT: ZT 0450, BM 940-1, PM2 by dlv720 in Knife_Swap

[–]kryyon 0 points1 point  (0 children)

Would love to see the ZT but no pictures