Open Joffinn opened 6 years ago
FYI my config file looks like this:
input {
azurewadtable {
account_name => "STORAGE ACCOUNT NAME"
access_key => "STORAGE ACCESS KEY"
table_name => "TABLE NAME"
}
}
output {
elasticsearch {
hosts => "[10.0.2.100:9200]"
index => "wad"
}
}
my guess is that I did something wrong with output but I don't see what.
@Joffinn , Firstly, please try the simplest debug output like this to see if you can see the output:
output {
stdout {
codec => rubydebug
}
}
If yes, then, try elasticsearch output plugin with default index:
output {
elasticsearch {
hosts => "[10.0.2.100:9200]"
}
}
If you do want to customize index, give it a hard-coded value will not take you anywhere. Please refer the document here to setup the index parameter: https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-index.
@Joffinn, It has been a while, did you get any chance to try the bare-bone configuration out?
@xiaomi7732 a colleague of mine found the trick to make it run. We had to comment the azurewadtable.rb file line 81 such as ` #for i in 0..99
#end # for block`
And suddenly it worked like a charm
She found this from some other thread but we still didn't understand why we needed to do so in order to have the plugin running properly.
@Joffinn, Really appreciate your input! @clguimanMSFT, Could you please follow up a bit on this issue?
@Joffinn The commented out lines just extend the query to include more types of data. Sometimes the partition key can also include
@clguimanMSFT atm I only have access to these tables through LinqPad But PartitionKey column looks like this Hope it helps
`
0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441768000000000 0636441768000000000 0636441768000000000 0636441768000000000 0636441768000000000 0636441768000000000 0636441768000000000 0636441768000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000
0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441762000000000 0636441768000000000 0636441768000000000 0636441768000000000 0636441768000000000 0636441768000000000 0636441768000000000 0636441768000000000 0636441768000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000 0636441774000000000
`
@Joffinn Can you please set the log level to 'debug' (https://www.elastic.co/guide/en/logstash/current/logging.html) and capture the traces emmited by the azurewadtable plugin? It should at least include the full query, any exceptions and anything before "[filter_duplicates] ... new item"
@Joffinn you accidentally leaked your storage key, you should reset it :) The logs provided only show the initialization part of the plugin, there are no logs with the actual query running. You should see something like "Query filter: "
Hi,
We have our logs in azure cloud, so far we were using linqpad to read them. I'm setting up ELK so we could analyse them in a more effective way.
following all instruction for https://github.com/Azure/azure-diagnostics-tools/tree/master/Logstash/logstash-input-azurewadtable I'm still unable to get any data.
I changed the collection start time for a date in past, still nothing more than what is below.
Am I totally missing something here?