kottapar / scripts_and_filters

A collection of scripts and logstash filters
10 stars 2 forks source link

error in logstash #2

Open Emrod82 opened 3 years ago

Emrod82 commented 3 years ago

I have problem with implementing it it's missing pattern folder with files....

Emrod82 commented 3 years ago

eg.

[2021-09-05T19:50:15,756][ERROR][logstash.javapipeline ][main] Pipeline error {:pipeline_id=>"main", :exception=>#<Grok::PatternError: pattern %{aix_reboot_time:reboot-time} not defined>, :backtrace=>["/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/jls-grok-0.11.5/lib/grok-pure.rb:123:in block in compile'", "org/jruby/RubyKernel.java:1442:inloop'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/jls-grok-0.11.5/lib/grok-pure.rb:93:in compile'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-grok-4.4.0/lib/logstash/filters/grok.rb:282:inblock in register'", "org/jruby/RubyArray.java:1820:in each'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-grok-4.4.0/lib/logstash/filters/grok.rb:276:inblock in register'", "org/jruby/RubyHash.java:1415:in each'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-grok-4.4.0/lib/logstash/filters/grok.rb:271:inregister'", "org/logstash/config/ir/compiler/AbstractFilterDelegatorExt.java:75:in register'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:228:inblock in register_plugins'", "org/jruby/RubyArray.java:1820:in each'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:227:inregister_plugins'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:586:in maybe_setup_out_plugins'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:240:instart_workers'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:185:in run'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:137:inblock in start'"], "pipeline.sources"=>["/etc/logstash/conf.d/05-unix.conf"], :thread=>"#"} [2021-09-05T19:50:15,757][INFO ][logstash.javapipeline ][main] Pipeline terminated {"pipeline.id"=>"main"} [2021-09-05T19:50:15,768][ERROR][logstash.agent ] Failed to execute action {:id=>:main, :action_type=>LogStash::ConvergeResult::FailedAction, :message=>"Could not execute action: PipelineAction::Create

, action_result: false", :backtrace=>nil}

kottapar commented 3 years ago

You're correct. The pattern folder is missing. However it should be easy to define the timestamp pattern. I gave an example in https://kottapar.medium.com/how-we-centralized-our-logs-using-elk-stack-6a5a73c1e94c for errpt timestamp. I'll see if I still have the code and will add it.