Mailing List Archive

ntopng and elasticsearch integration
Hi, I have been running the following:

Ntopng (ARM) on a Raspberry Pi3 - no problems
ElasticSearch 5.6.2 ad Kibana 5.6.2

I have been using an export of ntopng via command line on my Pi3 as follows:

Sudo ntopng -F "es;flows;ntopng%M.%d.%y;http://192.168.251.30:9200/_bulk;" without any issues.

I then installed the X-pack plugin for ElasticSearch and Kibana - which includes security (basic auth). I changed the elasticsearch database user password.

So - when I pass #Sudo ntopng -F "es;flows;ntopng%M.%d.%y;http://192.168.251.30:9200/_bulk;elastic:elasticpassword;"

I get responses from ntopng "cannot resolve hostname "elastic:elasticpassword" Do I need a pro/small business license because of authentication?

christina phillips
Re: ntopng and elasticsearch integration [ In reply to ]
Hi,

What is the ntopng version you are using?

ES authentication is supported, however, it seems that you have a extra ; after your elasticpassword. Also the double quotes doesn't seem the standard ones. Please check.

> On 12 Oct 2017, at 00:10, Christina Phillips <cphillips@inei.com> wrote:
>
> Hi, I have been running the following:
>
> Ntopng (ARM) on a Raspberry Pi3 - no problems
> ElasticSearch 5.6.2 ad Kibana 5.6.2
>
> I have been using an export of ntopng via command line on my Pi3 as follows:
>
> Sudo ntopng -F “es;flows;ntopng%M.%d.%y;http://192.168.251.30:9200/_bulk <http://192.168.251.30:9200/_bulk>;” without any issues.
>
> I then installed the X-pack plugin for ElasticSearch and Kibana – which includes security (basic auth). I changed the elasticsearch database user password.
>
> So – when I pass #Sudo ntopng -F “es;flows;ntopng%M.%d.%y;http://192.168.251.30:9200/_bulk;elastic:elasticpassword <http://192.168.251.30:9200/_bulk;elastic:elasticpassword>;”
>
> I get responses from ntopng “cannot resolve hostname “elastic:elasticpassword” Do I need a pro/small business license because of authentication?
>
> CHRISTINA PHILLIPS
>
> _______________________________________________
> Ntop mailing list
> Ntop@listgateway.unipi.it <mailto:Ntop@listgateway.unipi.it>
> http://listgateway.unipi.it/mailman/listinfo/ntop <http://listgateway.unipi.it/mailman/listinfo/ntop>
Re: ntopng and elasticsearch integration [ In reply to ]
Hi,

What is the ntopng version you are using?

ES authentication is supported, however, it seems that you have a extra ; after your elasticpassword. Also the double quotes doesn't seem the standard ones. Please check.

> On 12 Oct 2017, at 00:10, Christina Phillips <cphillips@inei.com> wrote:
>
> Hi, I have been running the following:
>
> Ntopng (ARM) on a Raspberry Pi3 - no problems
> ElasticSearch 5.6.2 ad Kibana 5.6.2
>
> I have been using an export of ntopng via command line on my Pi3 as follows:
>
> Sudo ntopng -F “es;flows;ntopng%M.%d.%y;http://192.168.251.30:9200/_bulk <http://192.168.251.30:9200/_bulk>;” without any issues.
>
> I then installed the X-pack plugin for ElasticSearch and Kibana – which includes security (basic auth). I changed the elasticsearch database user password.
>
> So – when I pass #Sudo ntopng -F “es;flows;ntopng%M.%d.%y;http://192.168.251.30:9200/_bulk;elastic:elasticpassword <http://192.168.251.30:9200/_bulk;elastic:elasticpassword>;”
>
> I get responses from ntopng “cannot resolve hostname “elastic:elasticpassword” Do I need a pro/small business license because of authentication?
>
> CHRISTINA PHILLIPS
>
> _______________________________________________
> Ntop mailing list
> Ntop@listgateway.unipi.it <mailto:Ntop@listgateway.unipi.it>
> http://listgateway.unipi.it/mailman/listinfo/ntop <http://listgateway.unipi.it/mailman/listinfo/ntop>
Re: ntopng and elasticsearch integration [ In reply to ]
I will have to get back to you on Monday. I will have access to the unit again at that time. I have not changed the way the manual command was entered on my Raspberry Pi3 in regards of the quotes – but maybe I did something wrong?

From: ntop-bounces@listgateway.unipi.it [mailto:ntop-bounces@listgateway.unipi.it] On Behalf Of Simone Mainardi
Sent: Thursday, October 12, 2017 4:45 AM
To: ntop@unipi.it
Cc: ntop@listgateway.unipi.it
Subject: Re: [Ntop] ntopng and elasticsearch integration

Hi,

What is the ntopng version you are using?

ES authentication is supported, however, it seems that you have a extra ; after your elasticpassword. Also the double quotes doesn't seem the standard ones. Please check.

On 12 Oct 2017, at 00:10, Christina Phillips <cphillips@inei.com<mailto:cphillips@inei.com>> wrote:

Hi, I have been running the following:

Ntopng (ARM) on a Raspberry Pi3 - no problems
ElasticSearch 5.6.2 ad Kibana 5.6.2

I have been using an export of ntopng via command line on my Pi3 as follows:

Sudo ntopng -F “es;flows;ntopng%M.%d.%y;http://192.168.251.30:9200/_bulk;” without any issues.

I then installed the X-pack plugin for ElasticSearch and Kibana – which includes security (basic auth). I changed the elasticsearch database user password.

So – when I pass #Sudo ntopng -F “es;flows;ntopng%M.%d.%y;http://192.168.251.30:9200/_bulk;elastic:elasticpassword;”

I get responses from ntopng “cannot resolve hostname “elastic:elasticpassword” Do I need a pro/small business license because of authentication?

CHRISTINA PHILLIPS

_______________________________________________
Ntop mailing list
Ntop@listgateway.unipi.it<mailto:Ntop@listgateway.unipi.it>
http://listgateway.unipi.it/mailman/listinfo/ntop
Re: ntopng and elasticsearch integration [ In reply to ]
So, I am running 3.1.170712<https://github.com/ntop/ntopng/commit/a16f6f937d5d039a1186c53f8e0d98951c836a5d> - Pro [Small Business Edition]/Embedded Edition (I bought the license on Saturday).

I downgraded the ELK stack to 5.5.0 because of other issues. I am able to run with 5.5.0 and the X-Pack plugin set – I noticed a few differences. I also did not need the semicolon after the password.



From: ntop-bounces@listgateway.unipi.it [mailto:ntop-bounces@listgateway.unipi.it] On Behalf Of Simone Mainardi
Sent: Thursday, October 12, 2017 4:45 AM
To: ntop@unipi.it
Cc: ntop@listgateway.unipi.it
Subject: Re: [Ntop] ntopng and elasticsearch integration

Hi,

What is the ntopng version you are using?

ES authentication is supported, however, it seems that you have a extra ; after your elasticpassword. Also the double quotes doesn't seem the standard ones. Please check.

On 12 Oct 2017, at 00:10, Christina Phillips <cphillips@inei.com<mailto:cphillips@inei.com>> wrote:

Hi, I have been running the following:

Ntopng (ARM) on a Raspberry Pi3 - no problems
ElasticSearch 5.6.2 ad Kibana 5.6.2

I have been using an export of ntopng via command line on my Pi3 as follows:

Sudo ntopng -F “es;flows;ntopng%M.%d.%y;http://192.168.251.30:9200/_bulk;” without any issues.

I then installed the X-pack plugin for ElasticSearch and Kibana – which includes security (basic auth). I changed the elasticsearch database user password.

So – when I pass #Sudo ntopng -F “es;flows;ntopng%M.%d.%y;http://192.168.251.30:9200/_bulk;elastic:elasticpassword;”

I get responses from ntopng “cannot resolve hostname “elastic:elasticpassword” Do I need a pro/small business license because of authentication?

CHRISTINA PHILLIPS

_______________________________________________
Ntop mailing list
Ntop@listgateway.unipi.it<mailto:Ntop@listgateway.unipi.it>
http://listgateway.unipi.it/mailman/listinfo/ntop
Re: ntopng and elasticsearch integration [ In reply to ]
So, I am running 3.1.170712<https://github.com/ntop/ntopng/commit/a16f6f937d5d039a1186c53f8e0d98951c836a5d> - Pro [Small Business Edition]/Embedded Edition (I bought the license on Saturday).

I downgraded the ELK stack to 5.5.0 because of other issues. I am able to run with 5.5.0 and the X-Pack plugin set – I noticed a few differences. I also did not need the semicolon after the password.



From: ntop-bounces@listgateway.unipi.it [mailto:ntop-bounces@listgateway.unipi.it] On Behalf Of Simone Mainardi
Sent: Thursday, October 12, 2017 4:45 AM
To: ntop@unipi.it
Cc: ntop@listgateway.unipi.it
Subject: Re: [Ntop] ntopng and elasticsearch integration

Hi,

What is the ntopng version you are using?

ES authentication is supported, however, it seems that you have a extra ; after your elasticpassword. Also the double quotes doesn't seem the standard ones. Please check.

On 12 Oct 2017, at 00:10, Christina Phillips <cphillips@inei.com<mailto:cphillips@inei.com>> wrote:

Hi, I have been running the following:

Ntopng (ARM) on a Raspberry Pi3 - no problems
ElasticSearch 5.6.2 ad Kibana 5.6.2

I have been using an export of ntopng via command line on my Pi3 as follows:

Sudo ntopng -F “es;flows;ntopng%M.%d.%y;http://192.168.251.30:9200/_bulk;” without any issues.

I then installed the X-pack plugin for ElasticSearch and Kibana – which includes security (basic auth). I changed the elasticsearch database user password.

So – when I pass #Sudo ntopng -F “es;flows;ntopng%M.%d.%y;http://192.168.251.30:9200/_bulk;elastic:elasticpassword;”

I get responses from ntopng “cannot resolve hostname “elastic:elasticpassword” Do I need a pro/small business license because of authentication?

CHRISTINA PHILLIPS

_______________________________________________
Ntop mailing list
Ntop@listgateway.unipi.it<mailto:Ntop@listgateway.unipi.it>
http://listgateway.unipi.it/mailman/listinfo/ntop