Configuring the Filebeat Service

To configure the Filebeat service, complete the following steps:

Procedure

  1. Open the Discover Network Capture Application and access the Beats tab.
  2. Click Download current.
    The latest configuration file downloads to your system.
  3. Open the downloaded file and modify the following sections in the file:
    1. Within the ElasticSearch Output section of the file, provide the IP address and the port number (9200) of the server running an instance of the Elastic search engine.
    2. Within the FileBeat inputs section of the file, provide the path or paths to pick the data.
    3. By default, the value of enabled is false. Set it to true.
  4. Save the file.
  5. Click Choose file.
  6. Navigate to the path containing the modified file and select the file.
    A success message appears.