and the output from Filebeat 6.4.2 in Kibana is showing in field error.message:
Provided Grok expressions do not match field value: [::ffff:10.5.1.62 - - [05/Nov/2018:15:39:18 +0000] \"GET /config HTTP/1.1\" 304 - \"https://myserver.com/\" \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.67 Safari/537.36\"]
Ok, if I add another annotation to the Kubernetes container:
co.elastic.logs/fileset.stdout: access
then all the log lines are parsed correctly. It is very odd to me that a) some log lines would parse correctly without this annotation and some would not, and that b) this wouldn't be the default.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.