Closed Venkat49k closed 5 years ago
input {
beats {
port => 5044
ssl => true
ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
ssl_key => "/etc/pki/tls/private/logstash-forwarder.key"
}
}
filter {
if [type] == "syslog" {
grok {
match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:[%{POSINT:syslog_pid}])?: %{GREEDYDATA:syslog_message}" }
add_field => [ "received_at", "%{@timestamp}" ]
add_field => [ "received_from", "%{host}" ]
}
syslog_pri { }
date {
match => [ "syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]
}
}
}
output {
elasticsearch {
hosts => ["localhost:9200"]
sniffing => true
manage_template => false
index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
document_type => "%{[@metadata][type]}"
}
}
Please help me in resolving this issue, as I was struck for multiple days :-(
Can you share the output of curl <es-host>:9200/filebeat-*/_search?pretty
and curl <es-host>:9200/filebeat-*/_mapping?pretty
commands?
[root@ip-10-0-1-245 elasticsearch]# curl 10.0.1.245:9200/filebeat-*/_search?pretty
{
"took" : 76,
"timed_out" : false,
"_shards" : {
"total" : 45,
"successful" : 45,
"failed" : 0
},
"hits" : {
"total" : 12185546,
"max_score" : 1.0,
"hits" : [
{
"_index" : "filebeat-2019.04.02",
"_type" : "log",
"_id" : "AWneFpA7G1ov5HMGBkRS",
"_score" : 1.0,
"_source" : {
"count" : 1,
"input_type" : "log",
"message" : "\tat org.springframework.beans.factory.support.ConstructorResolver.instantiate(ConstructorResolver.java:620)",
"source" : "/opt/taxilla/logs/taxilla.log",
"@timestamp" : "2019-04-02T12:46:53.037Z",
"@version" : "1",
"host" : "ip-10-0-1-79.us-west-2.compute.internal",
"tags" : [
"beats_input_codec_plain_applied"
],
"beat" : {
"name" : "ip-10-0-1-79.us-west-2.compute.internal",
"hostname" : "ip-10-0-1-79.us-west-2.compute.internal"
},
"fields" : null,
"offset" : 1398677,
"type" : "log"
}
},
{
"_index" : "filebeat-2019.04.02",
"_type" : "log",
"_id" : "AWneFpA7G1ov5HMGBkRV",
"_score" : 1.0,
"_source" : {
"count" : 1,
"input_type" : "log",
"message" : "\tat org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBeanInstance(AbstractAutowireCapableBeanFactory.java:1127)",
"source" : "/opt/taxilla/logs/taxilla.log",
"@timestamp" : "2019-04-02T12:46:53.037Z",
"@version" : "1",
"host" : "ip-10-0-1-79.us-west-2.compute.internal",
"tags" : [
"beats_input_codec_plain_applied"
],
"beat" : {
"name" : "ip-10-0-1-79.us-west-2.compute.internal",
"hostname" : "ip-10-0-1-79.us-west-2.compute.internal"
},
"fields" : null,
"offset" : 1399068,
"type" : "log"
}
},
{
"_index" : "filebeat-2019.04.02",
"_type" : "log",
"_id" : "AWneFpA7G1ov5HMGBkRX",
"_score" : 1.0,
"_source" : {
"count" : 1,
"input_type" : "log",
"message" : "\tat org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBean(AbstractAutowireCapableBeanFactory.java:498)",
"source" : "/opt/taxilla/logs/taxilla.log",
"@timestamp" : "2019-04-02T12:46:53.037Z",
"@version" : "1",
"host" : "ip-10-0-1-79.us-west-2.compute.internal",
"tags" : [
"beats_input_codec_plain_applied"
],
"beat" : {
"name" : "ip-10-0-1-79.us-west-2.compute.internal",
"hostname" : "ip-10-0-1-79.us-west-2.compute.internal"
},
"offset" : 1399353,
"fields" : null,
"type" : "log"
}
},
{
"_index" : "filebeat-2019.04.02",
"_type" : "log",
"_id" : "AWneFpA7G1ov5HMGBkRY",
"_score" : 1.0,
"_source" : {
"count" : 1,
"input_type" : "log",
"message" : "\tat org.springframework.beans.factory.support.AbstractBeanFactory.lambda$doGetBean$0(AbstractBeanFactory.java:320)",
"source" : "/opt/taxilla/logs/taxilla.log",
"@timestamp" : "2019-04-02T12:46:53.037Z",
"@version" : "1",
"host" : "ip-10-0-1-79.us-west-2.compute.internal",
"tags" : [
"beats_input_codec_plain_applied"
],
"beat" : {
"name" : "ip-10-0-1-79.us-west-2.compute.internal",
"hostname" : "ip-10-0-1-79.us-west-2.compute.internal"
},
"offset" : 1399490,
"fields" : null,
"type" : "log"
}
},
{
"_index" : "filebeat-2019.04.02",
"_type" : "log",
"_id" : "AWneFpA7G1ov5HMGBkRa",
"_score" : 1.0,
"_source" : {
"count" : 1,
"input_type" : "log",
"message" : "\tat org.springframework.beans.factory.support.AbstractBeanFactory.doGetBean(AbstractBeanFactory.java:318)",
"source" : "/opt/taxilla/logs/taxilla.log",
"@timestamp" : "2019-04-02T12:46:53.037Z",
"@version" : "1",
"host" : "ip-10-0-1-79.us-west-2.compute.internal",
"tags" : [
"beats_input_codec_plain_applied"
],
"beat" : {
"name" : "ip-10-0-1-79.us-west-2.compute.internal",
"hostname" : "ip-10-0-1-79.us-west-2.compute.internal"
},
"offset" : 1399732,
"fields" : null,
"type" : "log"
}
},
{
"_index" : "filebeat-2019.04.02",
"_type" : "log",
"_id" : "AWneFpA7G1ov5HMGBkRf",
"_score" : 1.0,
"_source" : {
"count" : 1,
"input_type" : "log",
"message" : "\tat org.springframework.context.annotation.AnnotationConfigApplicationContext.
[root@ip-10-0-1-245 elasticsearch]# curl 10.0.1.245:9200/filebeat-*/_mapping?pretty { "filebeat-2019.04.10" : { "mappings" : { "log" : { "properties" : { "@timestamp" : { "type" : "date" }, "@version" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "beat" : { "properties" : { "hostname" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "name" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } } } }, "count" : { "type" : "long" }, "host" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "input_type" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "message" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "offset" : { "type" : "long" }, "source" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "tags" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "type" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } } } } } }, "filebeat-2019.04.07" : { "mappings" : { "log" : { "properties" : { "@timestamp" : { "type" : "date" }, "@version" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "beat" : { "properties" : { "hostname" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "name" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } } } }, "count" : { "type" : "long" }, "host" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "input_type" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "message" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "offset" : { "type" : "long" }, "source" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "tags" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "type" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } } } } } }, "filebeat-2019.04.04" : { "mappings" : { "log" : { "properties" : { "@timestamp" : { "type" : "date" }, "@version" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "beat" : { "properties" : { "hostname" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "name" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } } } }, "count" : { "type" : "long" }, "host" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "input_type" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "message" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "offset" : { "type" : "long" }, "source" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "tags" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "type" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } } } } } }, "filebeat-2019.04.05" : { "mappings" : { "log" : { "properties" : { "@timestamp" : { "type" : "date" }, "@version" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "beat" : { "properties" : { "hostname" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "name" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } } } }, "count" : { "type" : "long" }, "host" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "input_type" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "message" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "offset" : { "type" : "long" }, "source" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "tags" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "type" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } } } } } }, "filebeat-2019.04.03" : { "mappings" : { "log" : { "properties" : { "@timestamp" : { "type" : "date" }, "@version" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "beat" : { "properties" : { "hostname" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "name" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } } } }, "count" : { "type" : "long" }, "host" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "input_type" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "message" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "offset" : { "type" : "long" }, "source" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "tags" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "type" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } } } } } }, "filebeat-2019.04.09" : { "mappings" : { "log" : { "properties" : { "@timestamp" : { "type" : "date" }, "@version" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "beat" : { "properties" : { "hostname" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "name" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } } } }, "count" : { "type" : "long" }, "host" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "input_type" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "message" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "offset" : { "type" : "long" }, "source" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "tags" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "type" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } } } } } }, "filebeat-2019.04.06" : { "mappings" : { "log" : { "properties" : { "@timestamp" : { "type" : "date" }, "@version" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "beat" : { "properties" : { "hostname" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "name" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } } } }, "count" : { "type" : "long" }, "host" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "input_type" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "message" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "offset" : { "type" : "long" }, "source" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "tags" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "type" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } } } } } }, "filebeat-2019.04.02" : { "mappings" : { "log" : { "properties" : { "@timestamp" : { "type" : "date" }, "@version" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "beat" : { "properties" : { "hostname" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "name" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } } } }, "count" : { "type" : "long" }, "host" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "input_type" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "message" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "offset" : { "type" : "long" }, "source" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "tags" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "type" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } } } } } }, "filebeat-2019.04.08" : { "mappings" : { "log" : { "properties" : { "@timestamp" : { "type" : "date" }, "@version" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "beat" : { "properties" : { "hostname" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "name" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } } } }, "count" : { "type" : "long" }, "host" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "input_type" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "message" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "offset" : { "type" : "long" }, "source" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "tags" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } }, "type" : { "type" : "text", "fields" : { "keyword" : { "type" : "keyword", "ignore_above" : 256 } } } } } } } }
I have ran those commands form the ELK server, please find the output.
Hi,
I think my issue was posted multiple times, still I am not able to figure out the mistake in my configuration. In Logtrail I am not seeing any data, please help me in resolving this issue. I am trying to pull the 'tomcat' logs from different server.
My logtrail conf file :