team!
I’ve got an issue when i try to start my container with logstash.
[2024-06-25T13:53:08,047][INFO ][logstash.inputs.udp ][main][ff352f2ccd0c89446b4546db6aa5ac501122eaef1754ce7230f4b66abd160420] Starting UDP listener {:address=>"sa27-vm-log-elk1.sam.loc:5044"}
[2024-06-25T13:53:08,049][ERROR][logstash.inputs.udp ][main][ff352f2ccd0c89446b4546db6aa5ac501122eaef1754ce7230f4b66abd160420] UDP listener died {:exception=>#<IPAddr::InvalidAddressError: invalid address: >, :backtrace=>["/usr/share/logstash/vendor/jruby/lib/ruby/stdlib/ipaddr.rb:684:in `in6_addr'", "/usr/share/logstash/vendor/jruby/lib/ruby/stdlib/ipaddr.rb:620:in `initialize'", "org/jruby/RubyClass.java:904:in `new'", "/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-input-udp-3.5.0/lib/logstash/inputs/udp.rb:115:in `udp_listener'", "/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/logstash-input-udp-3.5.0/lib/logstash/inputs/udp.rb:81:in `run'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:414:in `inputworker'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:405:in `block in start_input'"]}
[root@sa27-vm-log-elk1 elk]#
Here is my logstash.conf
input {
udp {
host => "0.0.0.0"
port => 5044
}
}
filter {}
output {
elasticsearch {
index => "logstash-%{+YYYY.MM.dd}"
hosts => ["http://es01:9200"]
user => "elastic"
password => "elastic1"
#ssl_enabled => true
# cacert => "/usr/share/logstash/certs/ca/ca.crt"
}
#stdout {}
}
And logstash.yml:
http.host: "0.0.0.0"
xpack.monitoring.elasticsearch.hosts: [ "http://es01:9200" ]
Service in docker-compose file:
logstash:
image: logstash:${STACK_VERSION}
labels:
co.elastic.logs/module: logstash
user: root
volumes:
- logstashdata01:/usr/share/logstash/data
- ./logstash/logstash.conf:/usr/local/data/elk/logstash/logstash.conf
environment:
- xpack.security.enabled=false
- xpack.security.http.ssl.enabled=false
- NODE_NAME="logstash"
- xpack.monitoring.enabled=false
- ELASTIC_USER=elastic
- ELASTIC_PASSWORD=${ELASTIC_PASSWORD}
- ELASTIC_HOSTS=http://es01:9200
command: logstash -f /usr/local/data/elk/logstash/logstash.conf
ports:
- "5044:5044/udp"
mem_limit: ${LS_MEM_LIMIT}
I understand that i miss or write wrong anything in block input
in logstash.conf, but i can’t understand what i do wrong.
I tried search information about this problem, but in internet another faults.
Can you help me?