-
SKIrcBot_ has quit
-
rojem_ has quit
-
rojem joined the channel
-
kyrill
they won't reconnect
-
kepper has quit
-
that's the thing - logstash isn't accepting new connections
-
I have a feeling that because its incoming connections are stuck in CLOSE_WAIT, nothing happens
-
ian_mac
well there is probably a connection limit
-
Guest70 joined the channel
-
or could be rather
-
idwer joined the channel
-
russorat joined the channel
-
ade_b has quit
-
calve joined the channel
-
calve
hello,
-
mleung joined the channel
-
JempInDaKella has quit
-
i have set a grok pattern, which works in the online debugger, which parse all the data I expect it to parse, but still tag my log as `_grokfailure`
-
pheaver has quit
-
SKIrcBot joined the channel
-
how can i investigate ?
-
filippos has quit
-
JempInDaKella joined the channel
-
filippos joined the channel
-
nevyn
calve: tab/space issues?
-
SKIrcBot has quit
-
calve
definitely not
-
SKIrcBot joined the channel
-
I mean, i exclusively use spaces, and I am not aware of any limitations
-
grok is not yaml, isn't ?
-
SKIrcBot has quit
-
my config is some syslog client read logs from files on the host, send it to logstash on a tcp input
-
nevyn
calve: in your own log?
-
bvi has quit
-
SKIrcBot joined the channel
-
spuder_ joined the channel
-
so I've found apps like to mess with my life by using tabs and or spaces.
-
I ended up writing some mutate stuff to just kill them with fire.
-
calve
it is a standard apache application
-
nevyn
so the gotach is copy the line out of the terminal paste into grokedebugger and it's now spaces and everything in the pattern works
-
so that's why I mention it.
-
calve
I understand
-
torrancew
kyrill: ok, that's more data to work wiht (sorry, was on a call)
-
calve
the thing is that logstash actually parse correctly the log
-
torrancew
kyrill: how many clients (LSF nodes) do you have?
-
calve
i can see all my custom fields in kibana, and none of them appears to be missing
-
rastro
calve: you only have one grok{}? Are you using the syslog input{} ?
-
torrancew
calve: ^^^ rastro is asking all the right questions
-
calve
rastro: i have multiple grok in my configuration, the other one works as expected
-
and no, i am not using syslog input
-
rastro
calve: are you using tag_on_failure?
-
soulair joined the channel
-
calve
rastro: no (can't find that string in my conf)
-
idwer has left the channel
-
rastro
-
logstashbot
-
kyrill has quit
-
calve
maybe the lack of GREEDYDATA is making it fail ?
-
SKIrcBot has quit
-
rastro
calve: you should set a unique one for each grok.
-
torrancew
calve: more likely your event is passing through more groks than you expect
-
and a /different/ one is tagging it _grokparsefail
-
SKIrcBot joined the channel
-
rastro
calve: you can match part of the input field; it doesn't have to be exhaustive.
-
calve
i will try a different tag_on_failure for each grok, and see the one that is failing
-
rastro waits patiently.
-
kyrill joined the channel
-
SKIrcBot joined the channel
-
squain has quit
-
Guest70 joined the channel
-
adaam has quit
-
Guest70 has quit
-
waouh
-
i have no failure anymore
-
jbehrends joined the channel
-
SKIrcBot has quit
-
InfraIrcBotTest joined the channel
-
nice
-
SKIrcBot joined the channel
-
thank you very much rastro and torrancew
-
ktosiek joined the channel
-
SKIrcBot_ joined the channel
-
rastro
calve: well, just adding tag_on_failure wouldn't fix the GPF...
-
calve
i cant read one of the tag i specified in kibana
-
jstoiko joined the channel
-
vodka_ joined the channel
-
Guest70 joined the channel
-
hulu1522 joined the channel
-
hulu1522_ joined the channel
-
vodka has quit
-
SKIrcBot__ joined the channel
-
SKIrcBot___ joined the channel
-
InfraIrcBotTest_ joined the channel
-
kyrill
getting somewhere now - looks like a few hosts are doing their level best to flatten the relay
-
is there a setting in logstash-forwarder to limit the batch size?
-
vodka_ has quit
-
torrancew
kyrill: a cli arg
-
wt0f joined the channel
-
-spool-size IIRC
-
_JZ_ has quit
-
JDiPierro has quit
-
kyrill
yeah found it
-
tomfoolry joined the channel
-
asimzaidi joined the channel
-
tomfoolry joined the channel
-
asimzaidi has quit
-
SKIrcBot_ has quit
-
SKIrcBot__ has quit
-
SKIrcBot has quit
-
SKIrcBot___ has quit
-
asimzaidi joined the channel
-
_Bryan_ has quit
-
SKIrcBot joined the channel
-
asimzaidi has quit
-
kjstone00_ joined the channel
-
hemu_ has quit
-
spuder joined the channel
-
colinsurprenant has quit
-
danofsatx joined the channel
-
danofsatx has quit
-
iamchrisf has quit
-
duckcpd joined the channel
-
SKIrcBot_ joined the channel
-
danofsatx joined the channel
-
filenox joined the channel
-
carlos_ has quit
-
InfraIrcBotTest_ has quit
-
InfraIrcBotTest has quit
-
brahama joined the channel
-
Sartsj joined the channel
-
duck_cpd has quit
-
withnale_ has quit
-
asimzaidi joined the channel
-
ian_mac, I think I've found the cause
-
it looks like the latest version of logstash-forwarder defaults to a batch size of 1024. Previously it was 100 (for me)
-
nathanleclaire joined the channel
-
120 nodes, all relaying to a single endpoint in batches of 1024 events flattened it.
-
that's my prevailing theory
-
InfraIrcBotTest joined the channel
-
danofsatx has quit
-
kepper joined the channel
-
palecur has quit
-
filenox has quit
-
danofsatx joined the channel
-
kepper has quit
-
RobertDupont joined the channel
-
wt0f has quit
-
wt0f joined the channel
-
wt0f has quit
-
jgorak_ joined the channel