Open RomanGz opened 8 years ago
Seems to be stable with syslog input instead of UDP, but they all get tagged with _grokparsefailure_sysloginput now - though whatever little parsing I'm doing works.
We had the same issue happen to us when we were using Logstash 5.0.0.
Well. We ended up feeding our multiline errors through syslog-ng to disk & read them in.
I think UDP packets just come in out of order & intertwined with each-other. We just have syslog-ng write out a file for each hosts that logstash reads in.
2 Logstash servers via RR DNS receiving Java stack traces via udp. After the error, it stops processing messages on that port. Port is still up & listening. We're listening on other ports as well, that are not multiline, and they continue working.
ERROR_LOG <%{NONNEGINT:prifacil}>(%{TIMESTAMP_ISO8601}|%{SYSLOGTIMESTAMP} %{DATA:src_host}) \(%{WORD:source_application}\)