Docker logs -> Filebeat container -> OpenSearch infra-logs
Ref T1624
Differential D2455
Collect logs from Docker dereckson on Jan 9 2022, 11:30. Authored by Tags None Referenced Files
Subscribers None
Details
Docker logs -> Filebeat container -> OpenSearch infra-logs Ref T1624 Collect logs from docker-001
Diff Detail
Event Timeline
Comment Actions OpenSearch. OpenSearch part looks good: we've the role and the user. Filebeat. Docker container runs, load the harvesters correctly, but use http and not https to try to connect to OpenSearch: {"level":"error","timestamp":"2022-01-09T21:51:06.179Z","logger":"publisher_pipeline_output","caller":"pipeline/output.go:154","message":"Failed to connect to backoff(elasticsearch(http://cloudhugger.nasqueron.org:9200)): Get \"http://cloudhugger.nasqueron.org:9200\": EOF"} Comment Actions {"level":"error","timestamp":"2022-01-09T21:54:40.939Z","logger":"publisher_pipeline_output","caller":"pipeline/output.go:154","message":"Failed to connect to backoff(elasticsearch(https://cloudhugger.nasqueron.org:9200)): Get \"https://cloudhugger.nasqueron.org:9200\": x509: certificate signed by unknown authority"} |