22. Graylog 3.0 Sidecar Windows Configuration

Sdílet
Vložit
  • čas přidán 10. 07. 2024
  • profile.php?...
    / bitsbytehard
    --------------------------------------------------------
    docs.graylog.org/en/3.0/pages/...

Komentáře • 34

  • @oxyiinc7518
    @oxyiinc7518 Před 4 lety +1

    Thanks for this! Finally got Greylog to work with Windows

  • @evainmatthias
    @evainmatthias Před 3 lety +1

    Great video ! simple, clear to understand and it works.
    And next time, windows search "cmd" and have immediately your command prompt ;)

  • @Mtsm3
    @Mtsm3 Před 4 lety +2

    awesome, works as a charm! super clear and understandable! thanks!

  • @BeavPlays
    @BeavPlays Před 5 lety

    Great tutorial, thank you! Got it working.

  • @shameerahasan6075
    @shameerahasan6075 Před 5 lety

    thanks for the video , very useful for sidecar configuration

  • @biondigiorgiogmail
    @biondigiorgiogmail Před 2 lety

    Great document - many thanks

  • @mumtazian
    @mumtazian Před 4 lety +1

    Thanks man, it helps

  • @casaaprile
    @casaaprile Před 4 lety

    have you tried using filebeat im having problems with sending out particular logs from IIS

    • @BitsByteHard
      @BitsByteHard  Před 4 lety

      so far no, but try to read this community.graylog.org/t/problem-with-filebeat-configuration-on-windows/9991
      hopefully you'll find the answer there

  • @HappyGepy
    @HappyGepy Před 4 lety

    Hi, the server API token is unique to each node ? Or could I use one token for group of computers (e.g. computers with Windows10)? Thanks for reply :-)

    • @BitsByteHard
      @BitsByteHard  Před 4 lety +1

      the api token is unique to every sidecar instance that you create and can be used by any windows/linux machines that want to send logs to graylog. let say you configure a sidecar for windows, you can use the same api token on 1 or more windows machines that you want to collect the logs from.

  • @oolyo6604
    @oolyo6604 Před rokem

    Thanks bro works good.
    I have only 1 issue winlogbeat only sends application and system logs not security logs

    • @BitsByteHard
      @BitsByteHard  Před rokem

      check what exactly your beat app monitors for or maybe your windows is not configured to send the right information

  • @shameerahasan6075
    @shameerahasan6075 Před 5 lety +1

    i am not getting the messages coming from the node , service is running on remote machine ,what would be the possible mistakes? sidecar beats shows message as failed

    • @BitsByteHard
      @BitsByteHard  Před 5 lety +1

      the tutorial was done on graylog version 3.0.1
      please make sure the graylog server and your windows machine match the time, they should be synced with ntp.
      more than this, please make sure you follow the tutorial step by step.
      making sure you'll have all of the above should work 100%

  • @nekooolay
    @nekooolay Před 2 lety +1

    How did you get the Graylog API url? I entered the same url as you entered but cannot be reached. Sorry

    • @BitsByteHard
      @BitsByteHard  Před rokem

      it might have changed, check the official doc

  • @krenn08
    @krenn08 Před 8 měsíci

    There's nothing listening on port 9000. At what point did we get that?

  • @benjaminlucas9818
    @benjaminlucas9818 Před 4 lety

    Can you help me I tried the steps above a couple of times but still no incoming message on my graylog server TIA

    • @BitsByteHard
      @BitsByteHard  Před 4 lety

      check your firewall, check to see if the date and time is the same, do a tcp dump to see if you actually get the messages on the interface

  • @techsupport8704
    @techsupport8704 Před 4 lety

    Tried the same instruction still not receiving any messages
    double checked the time zone both are in same zone with proper sync

    • @BitsByteHard
      @BitsByteHard  Před 4 lety

      try to review the steps and redo the process, it should work without any issues

  • @ozymandias_times9663
    @ozymandias_times9663 Před 4 lety

    Hi I get the error: faile to connect to backoff... tcp took too long to respond. I am using the same ip as my graylog

    • @BitsByteHard
      @BitsByteHard  Před 4 lety

      try to check the FW settings

    • @benjaminlucas9818
      @benjaminlucas9818 Před 4 lety

      same here . did you finally run yours?

    • @BitsByteHard
      @BitsByteHard  Před 4 lety

      @@benjaminlucas9818 most probably you are doing something somewhere wrong.... go through the steps again, check the date and time it must mach, check your ports you are listening on the graylog server, netstat -tulpn, check to see if the input is started.

    • @AgileSoluzioneresolvemos
      @AgileSoluzioneresolvemos Před 3 lety

      I need permit firewall, on CentOs for example is firewall-cmd --permanent --add-port=5044/tcp