0:01 AM
smerrill is now known as smerrill-offline
0:11 AM
NoodlesNZ joined the channel
0:17 AM
bfraser joined the channel
0:19 AM
RicardoSSP joined the channel
0:21 AM
richardm75 has quit
0:22 AM
bfraser has quit
0:25 AM
cakirke joined the channel
0:29 AM
hjjg
hi!
0:30 AM
what exactly should I do if I configured an input(tcp,json) and output(elasticsearch) which works just fine and logstash is eating up all my messages with NO debugging output after I add a filter?
0:30 AM
The logs are empty. No evidence of any configuration error. It silently drops everything. I'm using Logstash 1.4.2 on Ubuntu 14.04.
0:31 AM
I even started logstash with --debug (from /etc/default/logstash)
0:35 AM
0:35 AM
logstashbot
0:36 AM
bfraser joined the channel
0:37 AM
jerryitt joined the channel
0:39 AM
hjjg
I mean - what is wrong? Why is there no logging if something does not work? It just eats my messages. The are gone! No evidence, they ever existed.
0:42 AM
attractiveape
hjjg: You can start logstash with --debug for it to reveal the logic it's stepping through
0:42 AM
hjjg: not sure why it's eating your messages, sorry it's causing you grief
0:44 AM
nick_schuch|busy has left the channel
0:44 AM
hjjg
attractiveape: I tried --debug and -vv. When logstash starts, there is more output in the logfile. But there are no entries as soon as I input data.
0:46 AM
attractiveape: Also the stdout-Output is not working. Or I did not find the location of stdout from this daemon.
0:50 AM
kjstone00 joined the channel
0:57 AM
ggoZ has quit
0:58 AM
Exception in filterworker {"exception"=>#<NoMethodError: undefined method `&' for "sqli, id, lfi":String>, "backtrace"=>["/home/hg/logstash-1.4.2/lib/logstash/filters/base.rb:211:in `filter?'", "/home/hg/logstash-1.4.2/lib/logstash/filters/mutate.rb:204:in `filter'", "(eval):40:in `initialize'", "org/jruby/RubyProc.java:271:in `call'", "/home/hg/logstash-1.4.2/lib/logstash/pipeline.rb:262:in `filter'", ...
0:59 AM
... "/home/hg/logstash-1.4.2/lib/logstash/pipeline.rb:203:in `filterworker'", "/home/hg/logstash-1.4.2/lib/logstash/pipeline.rb:143:in `start_filters'"], :level=>:error}
0:59 AM
This is what you get if you download logstash as tar.gz and you run it with this command: bin/logstash -e 'input { tcp { type => "ids" port => 3333 format => "json" } } filter {geoip { type => "ids" add_tag => [ "geoip" ] source => "ip" } mutate { tags => [ "geoip" ] add_field => [ "coords", "%{geoip.longitude}", "tmplat", "%{geoip.latitude}" ] } } output { stdout { codec => rubydebug } }'
1:00 AM
The packages for Ubuntu do not display this error.
1:00 AM
virusuy has quit
1:04 AM
martineg_ has quit
1:06 AM
mkaesz joined the channel
1:10 AM
mkaesz has quit
1:10 AM
kjstone00 has quit
1:11 AM
savant joined the channel
1:11 AM
savant has left the channel
1:17 AM
stonith
upgraded to es 1.4.1 last night
1:18 AM
after the new index was created an hour ago or so in utc catchall * searches don't seem to work
1:18 AM
for the new index
1:18 AM
work fine in old one though
1:19 AM
oddly k4beta2 works too
1:28 AM
tphummel joined the channel
1:28 AM
tphummel has quit
1:41 AM
blitman_ joined the channel
1:43 AM
daito joined the channel
1:43 AM
blitman has quit
1:43 AM
blitman_ is now known as blitman
1:45 AM
smerrill-offline is now known as smerrill
1:45 AM
cakirke has quit
1:46 AM
RicardoSSP has quit
1:49 AM
smerrill is now known as smerrill-offline
1:58 AM
intransit joined the channel
2:13 AM
mdedetrich has quit
2:14 AM
mdedetrich joined the channel
2:17 AM
mdedetrich has quit
2:17 AM
KannOx joined the channel
2:18 AM
mdedetrich joined the channel
2:20 AM
BennyBoom joined the channel
2:20 AM
virusuy joined the channel
2:24 AM
frackster has quit
2:25 AM
BennyBoom has quit
2:25 AM
frackster joined the channel
2:26 AM
cassianoleal has quit
2:30 AM
perry has quit
2:30 AM
mdedetrich has quit
2:31 AM
virusuy_ joined the channel
2:32 AM
mdedetrich joined the channel
2:32 AM
NoodlesNZ has quit
2:34 AM
mdedetrich has quit
2:34 AM
virusuy has quit
2:36 AM
virusuy_ has quit
2:36 AM
virusuy joined the channel
2:39 AM
NoodlesNZ joined the channel
2:39 AM
mdedetrich joined the channel
2:40 AM
perry joined the channel
2:40 AM
perry is now known as Guest37942
2:41 AM
Guest37942 is now known as perryh
2:41 AM
perryh has quit
2:41 AM
perryh joined the channel
2:53 AM
tobleronegordon joined the channel
2:57 AM
luis_ joined the channel
2:58 AM
luis_
hi anyone can help me with a kibana question?
3:01 AM
pblittle joined the channel
3:05 AM
Damm
better off in #kibana
3:05 AM
but you can ask or don't expect an answer
3:07 AM
luis_
Damm thank you
3:08 AM
jerryitt has quit
3:16 AM
raeven joined the channel
3:16 AM
echelon
how about you just ask your question
3:19 AM
Mso150 joined the channel
3:30 AM
tobleronegordon has quit
3:30 AM
intransit has quit
3:33 AM
smerrill-offline is now known as smerrill
3:34 AM
chenryn joined the channel
3:35 AM
luis_ has quit
3:38 AM
smerrill is now known as smerrill-offline
3:49 AM
Mso150 has quit
3:50 AM
calavera joined the channel
3:53 AM
gauravarora joined the channel
3:58 AM
virusuy has quit
4:04 AM
gentunian has quit
4:08 AM
NoodlesNZ has quit
4:08 AM
untergeek joined the channel
4:09 AM
MugginsM has quit
4:15 AM
gauravarora has quit
4:18 AM
gauravarora joined the channel
4:28 AM
gauravarora has quit
4:31 AM
pblittle has quit
4:31 AM
daito has quit
4:34 AM
smerrill-offline is now known as smerrill
4:36 AM
perryh has quit
4:39 AM
smerrill is now known as smerrill-offline
4:42 AM
dbason has quit
4:43 AM
Arthur40A has quit
4:45 AM
incry6t1 has quit
4:47 AM
untergeek has quit
4:48 AM
calavera has quit
4:51 AM
gauravarora joined the channel
4:53 AM
perry joined the channel
4:53 AM
perry is now known as Guest95882
4:54 AM
Guest95882 is now known as perryh
4:54 AM
perryh has quit
4:54 AM
perryh joined the channel
5:05 AM
chenryn has quit
5:13 AM
qru has quit
5:15 AM
qru joined the channel
5:27 AM
daito joined the channel
5:31 AM
chenryn joined the channel
5:31 AM
daito has quit
5:33 AM
daito joined the channel
5:39 AM
tphummel joined the channel
5:40 AM
tphummel has quit
5:50 AM
smerrill-offline is now known as smerrill
5:50 AM
sathik joined the channel
5:53 AM
sathik has quit
5:53 AM
tphummel joined the channel
5:54 AM
cajoel has quit
5:55 AM
smerrill is now known as smerrill-offline
5:55 AM
tphummel has quit
5:56 AM
startuper joined the channel
5:58 AM
startuper
Hi
5:59 AM
anybody using logstash here?
6:01 AM
cajoel joined the channel
6:02 AM
ramteid joined the channel
6:12 AM
kireevco joined the channel
6:14 AM
SkyRocknRoll joined the channel
6:14 AM
SkyRocknRoll has quit
6:14 AM
SkyRocknRoll joined the channel
6:14 AM
he1kki joined the channel
6:34 AM
chenryn has quit
6:35 AM
chenryn joined the channel
6:38 AM
esfeed_untergeek has quit