11:29 AM
pawnbox has quit
11:29 AM
antgel joined the channel
11:33 AM
pawnbox_ joined the channel
11:35 AM
crazyphil
is it possible to regex match for/in the tags field? i.e. "if "/(.*)failure(.*)/" in tags?
11:37 AM
pawnbox_ has quit
11:38 AM
madpenguin has quit
11:38 AM
Kocane joined the channel
11:40 AM
Eilyre joined the channel
11:42 AM
ganeshraju1 joined the channel
11:43 AM
Eilyre_ joined the channel
11:45 AM
Eilyre has quit
11:48 AM
Eilyre_ has quit
11:49 AM
pawnbox joined the channel
11:49 AM
pawnbox has quit
11:50 AM
pawnbox joined the channel
11:51 AM
mpietersen joined the channel
11:53 AM
scl joined the channel
11:57 AM
luckyb56
warkolm: The gist you shared, it would re-index with the same name as you are using %{[@metadata][_index]}
11:58 AM
will logstash create temp index, delete it and re-index again? But I wanted to modify the original index name slightly i.e making 'logstash' to 'log'
11:59 AM
rembrand joined the channel
11:59 AM
ade_b has quit
12:00 PM
ade_b joined the channel
12:00 PM
ade_b has quit
12:00 PM
ade_b joined the channel
12:02 PM
ganeshraju joined the channel
12:03 PM
antgel has quit
12:04 PM
rembrand has quit
12:05 PM
antgel joined the channel
12:05 PM
casimirextreme has quit
12:06 PM
casimirextreme joined the channel
12:08 PM
radiocats joined the channel
12:10 PM
Eilyre joined the channel
12:11 PM
w1xz joined the channel
12:12 PM
kepper has quit
12:12 PM
ade_b joined the channel
12:12 PM
radiocats has quit
12:13 PM
pawnbox has quit
12:14 PM
SkyRocknRoll has quit
12:14 PM
Eilyre has quit
12:14 PM
Eilyre joined the channel
12:15 PM
pawnbox joined the channel
12:17 PM
wendelmineiro joined the channel
12:18 PM
ade_ joined the channel
12:18 PM
inqueue joined the channel
12:18 PM
ade_ has quit
12:18 PM
ade_b has quit
12:18 PM
ade_b joined the channel
12:19 PM
Eilyre has quit
12:19 PM
ade_b has quit
12:19 PM
ade_b joined the channel
12:20 PM
scl has quit
12:22 PM
inqueue has quit
12:23 PM
pawnbox has quit
12:24 PM
pawnbox joined the channel
12:24 PM
flowstate joined the channel
12:29 PM
flowstate has quit
12:32 PM
inqueue joined the channel
12:33 PM
Yaks has quit
12:33 PM
kepper joined the channel
12:33 PM
kepper has quit
12:33 PM
kepper joined the channel
12:35 PM
t4nk055 joined the channel
12:39 PM
derjohn_mob joined the channel
12:40 PM
radiocats joined the channel
12:40 PM
vali has quit
12:40 PM
radiocats joined the channel
12:41 PM
Eilyre joined the channel
12:45 PM
Eilyre_ joined the channel
12:45 PM
antgel has quit
12:46 PM
Eilyre has quit
12:50 PM
Eilyre_ has quit
12:53 PM
t4nk514 joined the channel
12:53 PM
t4nk514
hi
12:54 PM
i'm having some issues with timestamps, getting 2 hour offset (cause actual timestamp doesn't have Z).
12:55 PM
according to mr. google, when no Z is present, it automatically uses UTC
12:55 PM
i could replace tstamp to add +200 (europe), but that wouldn't work on daylightsaving calendar
12:56 PM
hence...my question: is there any way logstash to automatically use the CORRECT timestamp?
12:58 PM
k13nox_ has quit
12:59 PM
k13nox joined the channel
12:59 PM
_xela joined the channel
12:59 PM
Sandcrab has quit
12:59 PM
pawnbox has quit
13:07 PM
pandaadb
t4nk514, you can mutate it to the timezone you expect?
13:07 PM
13:07 PM
logstashbot
13:08 PM
pawnbox joined the channel
13:08 PM
pawnbox has quit
13:08 PM
pawnbox joined the channel
13:08 PM
mpietersen has quit
13:09 PM
t4nk514
pandaadb: what about daylight saving?
13:11 PM
pandaadb
I doubt you will be able to make that. I suggest changing your logging to log in UTC and then parse it as UTC
13:11 PM
revolt joined the channel
13:11 PM
_xela
hi - i'm brand new to logstash and i'm trying to use it for logs from a custom application
13:12 PM
Eilyre joined the channel
13:12 PM
the logs are json documents - one line, one json document
13:12 PM
pandaadb
I mean, DST isn't even a thing really? Half the time it's not used, then the other half it is on different days
13:13 PM
t4nk514, what you could do, but I highly do not recommend it, write your filters with if
13:13 PM
_xela
I've done a basic input/output config file, but i find a bit tricky managing them between codecs and filters
13:13 PM
pandaadb
so you do the date filter above but you could have them two. And then you go something like: If now() == Day of change THEN use the other timezone value
13:13 PM
t4nk514
pandaadb: now i discovered why...docker timezone
13:13 PM
thanks a lot!
13:14 PM
bye
13:14 PM
t4nk514 has quit
13:14 PM
pandaadb
sure .. :D
13:14 PM
losh joined the channel
13:14 PM
k13nox has quit
13:14 PM
_xela, do you have an example? I don't really get your question
13:14 PM
mikran has quit
13:15 PM
_xela
let me go to pastebin
13:16 PM
Eilyre_ joined the channel
13:16 PM
Eilyre has quit
13:17 PM
13:17 PM
logstashbot
13:17 PM
sharon
reinstall kibana
13:18 PM
phutchins2 joined the channel
13:18 PM
_xela
for the application data, everything works in elasticsearch
13:18 PM
for the bigdata not.
13:19 PM
ade_ joined the channel
13:19 PM
ade_ has quit
13:19 PM
pandaadb
do you mean your bigdata is not read at all?
13:19 PM
_xela
it's read, but
13:20 PM
pandaadb
I am not sure if that's (still) true, but I believe that you can not (or should not) have multiple input output filter
13:20 PM
_xela
[2016-04-29 13:20:01,567][DEBUG][action.bulk ] [Grotesk] [name-2016.04.29][4] failed to execute bulk item (index) index
13:20 PM
pandaadb
instead you should write it with one filter
13:20 PM
Eilyre_ has quit
13:21 PM
rem5 has quit
13:21 PM
oh okay, that seems something different
13:21 PM
xtruthx has quit
13:21 PM
sharon has quit
13:21 PM
rem5 joined the channel
13:22 PM
_xela_ joined the channel
13:22 PM
_xela_
when writing on file
13:22 PM
they are fine
13:23 PM
when sending to elastic, elastic is annoyed.
13:23 PM
pandaadb
interesting. Are the index names the same?
13:23 PM
For your app and bigdata parts I mean
13:24 PM
adaam has quit
13:24 PM
_xela_
as the log is not in the "message" key, but in the "data", and also the data is an hash of many key->value
13:24 PM
that can also nested
13:24 PM
not a leaf document
13:24 PM
yes, same index.
13:25 PM
good point. i could start separating them.
13:25 PM
_xela has quit
13:26 PM
flowstate joined the channel
13:27 PM
openweb joined the channel
13:27 PM
openweb
How do I run logstash with multiple config files?
13:28 PM
pandaadb
13:28 PM
logstashbot
13:30 PM
flowstate has quit
13:30 PM
flowstate joined the channel