13:10 PM
m4th
hey guys, do you know if elasticsearch does allocate mem ressource on each node with regard to memory available ?
13:11 PM
i.e I have a "light" node with 8G and two big nodes with 16G and I wonder if ES will smartly allocate more shards on big nodes to avoid "out of heap space" problems on the light one
13:12 PM
supersheep has quit
13:12 PM
itsmebp joined the channel
13:12 PM
vks joined the channel
13:12 PM
vks
hi
13:13 PM
how to drop a event in logstash ? I want to drop the message which doesn't match any of my grep pattern
13:14 PM
samdoran joined the channel
13:15 PM
bruntonspall has quit
13:15 PM
juicer2 joined the channel
13:15 PM
DaveANI has quit
13:16 PM
dblessing joined the channel
13:17 PM
viq
13:17 PM
logstashbot
Title: logstash - open source log management (at
logstash.net )
13:17 PM
viq
drop => true
13:17 PM
anonymuse joined the channel
13:19 PM
timl0101 has quit
13:19 PM
timl0101 joined the channel
13:20 PM
eper
multiline - does the log need to be be 'all together' in the file ?
13:20 PM
bruntonspall joined the channel
13:20 PM
think that makes no sense. Syslog file I have [a] cows \n [a] more cows \n [b] somebody else \n [a] last cow
13:21 PM
so i'm presuming multi log would need all the [a]'s together to treat them as 1 event, but as its syslog its got events inebwteen :/
13:21 PM
viq
eper: you need some way to group events together
13:21 PM
13:21 PM
logstashbot
Title: logstash - open source log management (at
logstash.net )
13:22 PM
viq
It does let you specify a pattern by which to group events
13:22 PM
eper
but how long would it keep looking for that pattern?
13:22 PM
piavlo has quit
13:23 PM
viq
That I don't know
13:23 PM
piavlo joined the channel
13:23 PM
supersheep joined the channel
13:24 PM
vks
viq: i have multiple grep pattern . if drop => true logstash is dropping all the event
13:24 PM
kaspergrubbe has quit
13:24 PM
viq
vks: or you could add tag with successful grep, and drop events without the tag
13:25 PM
vks
thats what i am doing now
13:25 PM
viq: but i want to remove tag i had added while grep was matched
13:28 PM
axellj joined the channel
13:29 PM
axellj has quit
13:32 PM
pablo_ has quit
13:33 PM
logstashbot
13:34 PM
_joes_ joined the channel
13:35 PM
kaspergrubbe joined the channel
13:38 PM
darkelda has quit
13:38 PM
Guest8419 has quit
13:38 PM
tarun joined the channel
13:39 PM
darkelda joined the channel
13:40 PM
loide joined the channel
13:40 PM
[diecast] has quit
13:41 PM
tarun__ has quit
13:42 PM
DaveANI joined the channel
13:43 PM
zeroXten joined the channel
13:45 PM
Infin1ty joined the channel
13:46 PM
adepasquale joined the channel
13:47 PM
zeroXten
I've got some logs in elasticsearch via logstash, and using kibana as a front end. The logs contain xml that have a field we'd like to use. Can this be done dynamically?
13:47 PM
ie after data is in elasticsearhc.. almost need some sort of plugin sitting between kibana and elasticsearch
13:48 PM
or in splunk i'd probably do a subsearch process xml and create a new field from the result
13:50 PM
DaveANI has quit
13:50 PM
vks
13:50 PM
logstashbot
13:50 PM
middleman_ has quit
13:54 PM
kubes joined the channel
13:55 PM
ksclarke joined the channel
13:57 PM
zeroXten
13:57 PM
logstashbot
Title: Feature Request: Support Client Generated Dynamic field searching/terms 路 Issue #121 路 rashidkpc/Kibana 路 GitHub (at
github.com )
13:57 PM
doxavore joined the channel
13:57 PM
SynchroM has quit
13:59 PM
BigBeerJR has quit
14:02 PM
webb has quit
14:02 PM
kjstone00 joined the channel
14:03 PM
14:08 PM
vks has quit
14:10 PM
SynchroM joined the channel
14:12 PM
cwebber joined the channel
14:13 PM
_pitchfork_ has quit
14:15 PM
_maes_ has quit
14:16 PM
tziOm has quit
14:16 PM
jberanek joined the channel
14:16 PM
DaveANI joined the channel
14:20 PM
io_syl joined the channel
14:21 PM
jberanek has quit
14:22 PM
johd has quit
14:23 PM
fignew joined the channel
14:25 PM
DaveANI has quit
14:26 PM
cyrus1 joined the channel
14:27 PM
cyrus1
if anybody is curious about the csv stuff I was chatting about last night… I went ahead and added a grok filter and pulled out what I needed :)
14:27 PM
webb joined the channel
14:28 PM
rhys joined the channel
14:29 PM
kubes has quit
14:29 PM
kubes joined the channel
14:30 PM
sqlnoob has quit
14:30 PM
nemish joined the channel
14:30 PM
sqlnoob joined the channel
14:30 PM
sqlnoob has quit
14:30 PM
[diecast] joined the channel
14:30 PM
[diecast] has quit
14:30 PM
[diecast] joined the channel
14:30 PM
kubes__ joined the channel
14:31 PM
sqlnoob joined the channel
14:34 PM
kubes has quit
14:37 PM
kubes__ has quit
14:37 PM
kubes joined the channel
14:38 PM
sqlnoob has quit
14:39 PM
kubes__ joined the channel
14:40 PM
clstokes joined the channel
14:41 PM
eper
hmm accidentally joined log stash to a 0.9x cluster. It appears to work but I know it is not supposed to
14:41 PM
kubes has quit
14:42 PM
alcy has quit
14:42 PM
devOpsEv
eper: regular ES output? really?
14:42 PM
eper
yeah hmm
14:42 PM
devOpsEv
eper: what version of ES?
14:42 PM
eper
1.13
14:42 PM
its not supposed to work it was an accidental puppet run changed outback back hmm
14:43 PM
its updating through kibana says so and no errors but i am sure its not supposed to join
14:43 PM
loide has quit
14:43 PM
loide joined the channel
14:43 PM
loide has quit
14:44 PM
loide joined the channel
14:44 PM
maybe it'll explode when it tries to create an index
14:44 PM
as its already created todays index so just updating
14:45 PM
stackedsax1 joined the channel
14:49 PM
timl0101_ joined the channel
14:49 PM
stackedsax1 has quit
14:50 PM
loide has quit
14:50 PM
loide joined the channel
14:51 PM
kubes__ has quit
14:51 PM
DaveANI joined the channel
14:51 PM
whack
eper: I've never seen elasticsearch 0.20 join a cluster with 0.90
14:51 PM
jamesturnbull: about 500 million events/day
14:51 PM
timl0101 has quit
14:51 PM
timl0101_ is now known as timl0101
14:51 PM
kubes joined the channel
14:52 PM
eper
don't disagree I'm sure it will explode come new index time
14:52 PM
DanGarthwaite joined the channel
14:52 PM
whack
no I mean
14:52 PM
it won't join
14:52 PM
eper
oh
14:52 PM
DanGarthwaite
Anyone try beaver with multiple upstream redis servers?
14:53 PM
whack
it will start, and may appear to work, but the cluster won't show any nodes with another version
14:53 PM
and the clustesr will be separate
14:53 PM
eper
hostname: search01a version: 0.90.2
14:53 PM
and logs are appearing O-o
14:55 PM
[2013-07-31 14:36:31,581][INFO ][cluster.service ] [search01a] added {[Obliterator][UeHMRR31S9SoglIxVFAmgw][inet[/212.23.x.x:9300]]{client=true, data=false},}, reason: zen-disco-receive(join from node[[Obliterator][UeHMRR31S9SoglIxVFAmgw][inet[/212.23.x.x:9300]]{client=true, data=false}])
14:56 PM
kubes has quit
14:56 PM
oh wells i did intend to use _http output but puppet ran and put it back without me noticing
14:58 PM
adepasquale has quit
14:59 PM
adamjt joined the channel
14:59 PM
adepasquale joined the channel
14:59 PM
DaveANI has quit
15:01 PM
adamjt
In the grep filter, if I have several good-sized patterns that I want to match against in an OR fashion, is it possible to split it into several lines without breaking the matching?
15:02 PM
whack
adamjt: not at this time