Afternoon all - I'm having issues shipping both nginx access and error logs to Logstash, using Filebeat. Access logs appear to be shipping, and Logstash appears to be receiving error logs (with debug log level, I see a number of "output received" messages for error log entries), but they do not appear in the target index.
Can anyone shed any light on this please? It's getting very frustrating to see the logs arriving, but not appearing in the ES index.
jesusaur joined the channel
pawnbox has quit
yardenbar joined the channel
rastro joined the channel
rastro has quit
hugh_jass joined the channel
cablekevin joined the channel
Gotxi joined the channel
Gotxi
Hi guys! quick question:
can i match with grok a field on a message and then based on the value of a field, make a specific grok?
something like: host=badum,typefield=type1 interval=10 value=5 and then "if typefield=type1: grok this way. else if typefield=type2: grok that other way"
pawnbox joined the channel
Seidr
Ah - if anyone wants to know *why* I wasn't seeing my nginx error logs appearing - access logs have the timezone (+0300), where as the error logs did not. My error logs were appearing three hours ahead. Have added a mutate to mitigate.
Check in nginx.yml, where I'm switching between source.
Gotxi
cool! this should work
thanks man
hmm i see it is not exactly what i need, on filebeat you already specify a source, i dont know what my source is unless i do a initial grok. Then based on the source by that initial grok, i would like to grok again with a specific pattern according to the source
pawnbox has quit
pawnbox joined the channel
hugh_jass joined the channel
kchan joined the channel
Gotxi has quit
pawnbox has quit
pawnbox joined the channel
al-damiri joined the channel
kchan has quit
pkdubey4u joined the channel
gunzy83 joined the channel
gunzy83 has quit
Seidr has quit
hugh_jass joined the channel
darkmoonvt joined the channel
pkdubey4u has quit
Sandcrab has quit
Lap64_ has quit
yardenbar has quit
yardenbar joined the channel
pew has left the channel
pawnbox has quit
yardenbar has quit
gentunian joined the channel
hugh_jass joined the channel
LJ23 joined the channel
pawnbox joined the channel
yardenbar joined the channel
pawnbox has quit
pawnbox joined the channel
hugh_jass joined the channel
b8se11 joined the channel
phutchins1 has quit
sndcrb joined the channel
pawnbox has quit
pawnbox joined the channel
hugh_jass joined the channel
matejz joined the channel
yardenbar has quit
yardenbar joined the channel
yardenbar has quit
cyborg-one joined the channel
Itkovian has quit
kcas_ joined the channel
hugh_jass joined the channel
kchan joined the channel
Darcidride joined the channel
LJ23 has quit
pawnbox has quit
matejz has quit
Koma
Can I apply a filter on looping on all fields starting with _keyword_ ?
Can I apply a filter looping on all fields starting with _keyword_ ?