gistfile1.txt
Aug 30 12:36:36 zeek1 filebeat[1043633]: {"log.level":"info","@timestamp":"2023-08-30T12:36:36.486Z","log.logger":"monitoring","log.origin":{"file.name":"log/log.go","file.line":187},"message":"Non-zero metrics in the last 30s","service.name":"filebeat","monitoring":{"metrics":{"beat":{"cgroup":{"memory":{"mem":{"usage":{"bytes":175747072}}}},"cpu":{"system":{"ticks":727160,"time":{"ms":640}},"total":{"ticks":10709890,"time":{"ms":9620},"value":10709890},"user":{"ticks":9982730,"time":{"ms":8980}}},"handles":{"limit":{"hard":524288,"soft":524288},"open":31},"info":{"ephemeral_id":"14379ec3-8426-41d1-9744-eb7d5f2c21db","uptime":{"ms":55920113},"version":"8.9.1"},"memstats":{"gc_next":125759528,"memory_alloc":93990456,"memory_total":635123006592,"rss":227827712},"runtime":{"goroutines":310}},"filebeat":{"events":{"active":1209,"added":21952,"done":21992},"harvester":{"open_files":19,"running":19,"started":2}},"libbeat":{"config":{"module":{"running":2}},"output":{"events":{"acked":22599,"active":0,"batches":457,"total":22549},"read":{"bytes":5045467},"write":{"bytes":42587969}},"pipeline":{"clients":38,"events":{"active":0,"filtered":2,"published":21950,"total":21952},"queue":{"acked":22599}}},"registrar":{"states":{"current":20,"update":22601},"writes":{"success":23,"total":23}},"system":{"load":{"1":1.73,"15":1.76,"5":1.86,"norm":{"1":0.0432,"15":0.044,"5":0.0465}}}},"ecs.version":"1.6.0"}}
Aug 30 12:37:06 zeek1 filebeat[1043633]: {"log.level":"info","@timestamp":"2023-08-30T12:37:06.487Z","log.logger":"monitoring","log.origin":{"file.name":"log/log.go","file.line":187},"message":"Non-zero metrics in the last 30s","service.name":"filebeat","monitoring":{"metrics":{"beat":{"cgroup":{"memory":{"mem":{"usage":{"bytes":147128320}}}},"cpu":{"system":{"ticks":727950,"time":{"ms":790}},"total":{"ticks":10718740,"time":{"ms":8850},"value":10718740},"user":{"ticks":9990790,"time":{"ms":8060}}},"handles":{"limit":{"hard":524288,"soft":524288},"open":31},"info":{"ephemeral_id":"14379ec3-8426-41d1-9744-eb7d5f2c21db","uptime":{"ms":55950114},"version":"8.9.1"},"memstats":{"gc_next":98144856,"memory_alloc":68789208,"memory_total":635649822096,"rss":203124736},"runtime":{"goroutines":310}},"filebeat":{"events":{"active":815,"added":19926,"done":20320},"harvester":{"open_files":19,"running":19}},"libbeat":{"config":{"module":{"running":2}},"output":{"events":{"acked":19183,"active":0,"batches":390,"total":19183},"read":{"bytes":4282996},"write":{"bytes":36137618}},"pipeline":{"clients":38,"events":{"active":743,"published":19926,"total":19926},"queue":{"acked":19183}}},"registrar":{"states":{"current":20,"update":19183},"writes":{"success":20,"total":20}},"system":{"load":{"1":1.51,"15":1.74,"5":1.79,"norm":{"1":0.0378,"15":0.0435,"5":0.0448}}}},"ecs.version":"1.6.0"}}
Aug 30 12:37:17 zeek1 filebeat[1043633]: {"log.level":"info","@timestamp":"2023-08-30T12:37:17.267Z","log.logger":"input.harvester","log.origin":{"file.name":"log/harvester.go","file.line":342},"message":"File is inactive. Closing because close_inactive of 5m0s reached.","service.name":"filebeat","input_id":"9ae4765b-23f2-4be3-a4d9-3390f892eaba","source_file":"/mnt/Bro/current/pe.log","state_id":"native::5113074-64768","finished":false,"os_id":"5113074-64768","old_source":"/mnt/Bro/current/pe.log","old_finished":true,"old_os_id":"5113074-64768","harvester_id":"2773546e-18b3-422e-a972-2163dc84d968","ecs.version":"1.6.0"}
Aug 30 12:37:36 zeek1 filebeat[1043633]: {"log.level":"info","@timestamp":"2023-08-30T12:37:36.487Z","log.logger":"monitoring","log.origin":{"file.name":"log/log.go","file.line":187},"message":"Non-zero metrics in the last 30s","service.name":"filebeat","monitoring":{"metrics":{"beat":{"cgroup":{"memory":{"mem":{"usage":{"bytes":171511808}}}},"cpu":{"system":{"ticks":728530,"time":{"ms":580}},"total":{"ticks":10727980,"time":{"ms":9240},"value":10727980},"user":{"ticks":9999450,"time":{"ms":8660}}},"handles":{"limit":{"hard":524288,"soft":524288},"open":30},"info":{"ephemeral_id":"14379ec3-8426-41d1-9744-eb7d5f2c21db","uptime":{"ms":55980116},"version":"8.9.1"},"memstats":{"gc_next":148547680,"memory_alloc":118174264,"memory_total":636228109800,"rss":235917312},"runtime":{"goroutines":306}},"filebeat":{"events":{"active":691,"added":21954,"done":22078},"harvester":{"closed":1,"open_files":18,"running":18}},"libbeat":{"config":{"module":{"running":2}},"output":{"events":{"acked":22405,"active":50,"batches":455,"total":22455},"read":{"bytes":5002150},"write":{"bytes":41711394}},"pipeline":{"clients":38,"events":{"active":291,"filtered":1,"published":21953,"total":21954},"queue":{"acked":22405}}},"registrar":{"states":{"current":20,"update":22406},"writes":{"success":24,"total":24}},"system":{"load":{"1":1.73,"15":1.76,"5":1.83,"norm":{"1":0.0432,"15":0.044,"5":0.0458}}}},"ecs.version":"1.6.0"}}
Aug 30 12:38:06 zeek1 filebeat[1043633]: {"log.level":"info","@timestamp":"2023-08-30T12:38:06.487Z","log.logger":"monitoring","log.origin":{"file.name":"log/log.go","file.line":187},"message":"Non-zero metrics in the last 30s","service.name":"filebeat","monitoring":{"metrics":{"beat":{"cgroup":{"memory":{"mem":{"usage":{"bytes":161038336}}}},"cpu":{"system":{"ticks":729090,"time":{"ms":560}},"total":{"ticks":10736740,"time":{"ms":8760},"value":10736740},"user":{"ticks":10007650,"time":{"ms":8200}}},"handles":{"limit":{"hard":524288,"soft":524288},"open":30},"info":{"ephemeral_id":"14379ec3-8426-41d1-9744-eb7d5f2c21db","uptime":{"ms":56010118},"version":"8.9.1"},"memstats":{"gc_next":113520544,"memory_alloc":58563192,"memory_total":636760928488,"rss":223514624},"runtime":{"goroutines":306}},"filebeat":{"events":{"active":2075,"added":20267,"done":18883},"harvester":{"open_files":18,"running":18}},"libbeat":{"config":{"module":{"running":2}},"output":{"events":{"acked":19383,"active":50,"batches":395,"total":19383},"read":{"bytes":4327786},"write":{"bytes":36132486}},"pipeline":{"clients":38,"events":{"active":1175,"published":20267,"total":20267},"queue":{"acked":19383}}},"registrar":{"states":{"current":20,"update":19383},"writes":{"success":21,"total":21}},"system":{"load":{"1":1.78,"15":1.76,"5":1.83,"norm":{"1":0.0445,"15":0.044,"5":0.0458}}}},"ecs.version":"1.6.0"}}
Aug 30 12:38:36 zeek1 filebeat[1043633]: {"log.level":"info","@timestamp":"2023-08-30T12:38:36.486Z","log.logger":"monitoring","log.origin":{"file.name":"log/log.go","file.line":187},"message":"Non-zero metrics in the last 30s","service.name":"filebeat","monitoring":{"metrics":{"beat":{"cgroup":{"memory":{"mem":{"usage":{"bytes":160305152}}}},"cpu":{"system":{"ticks":729740,"time":{"ms":650}},"total":{"ticks":10747850,"time":{"ms":11110},"value":10747850},"user":{"ticks":10018110,"time":{"ms":10460}}},"handles":{"limit":{"hard":524288,"soft":524288},"open":30},"info":{"ephemeral_id":"14379ec3-8426-41d1-9744-eb7d5f2c21db","uptime":{"ms":56040114},"version":"8.9.1"},"memstats":{"gc_next":142105448,"memory_alloc":96297392,"memory_total":637449444304,"rss":224002048},"runtime":{"goroutines":305}},"filebeat":{"events":{"active":790,"added":25804,"done":27089},"harvester":{"open_files":18,"running":18}},"libbeat":{"config":{"module":{"running":2}},"output":{"events":{"acked":26472,"active":0,"batches":532,"total":26422},"read":{"bytes":5909576},"write":{"bytes":49783773}},"pipeline":{"clients":38,"events":{"active":507,"published":25804,"total":25804},"queue":{"acked":26472}}},"registrar":{"states":{"current":20,"update":26472},"writes":{"success":26,"total":26}},"system":{"load":{"1":2,"15":1.78,"5":1.88,"norm":{"1":0.05,"15":0.0445,"5":0.047}}}},"ecs.version":"1.6.0"}}
Aug 30 12:39:06 zeek1 filebeat[1043633]: {"log.level":"info","@timestamp":"2023-08-30T12:39:06.486Z","log.logger":"monitoring","log.origin":{"file.name":"log/log.go","file.line":187},"message":"Non-zero metrics in the last 30s","service.name":"filebeat","monitoring":{"metrics":{"beat":{"cgroup":{"memory":{"mem":{"usage":{"bytes":147726336}}}},"cpu":{"system":{"ticks":730410,"time":{"ms":670}},"total":{"ticks":10756830,"time":{"ms":8980},"value":10756830},"user":{"ticks":10026420,"time":{"ms":8310}}},"handles":{"limit":{"hard":524288,"soft":524288},"open":30},"info":{"ephemeral_id":"14379ec3-8426-41d1-9744-eb7d5f2c21db","uptime":{"ms":56070118},"version":"8.9.1"},"memstats":{"gc_next":125170552,"memory_alloc":112187784,"memory_total":638002537840,"rss":211312640},"runtime":{"goroutines":306}},"filebeat":{"events":{"active":1330,"added":20763,"done":20223},"harvester":{"open_files":18,"running":18}},"libbeat":{"config":{"module":{"running":2}},"output":{"events":{"acked":20840,"active":50,"batches":424,"total":20890},"read":{"bytes":4652834},"write":{"bytes":39442423}},"pipeline":{"clients":38,"events":{"active":430,"published":20763,"total":20763},"queue":{"acked":20840}}},"registrar":{"states":{"current":20,"update":20840},"writes":{"success":23,"total":23}},"system":{"load":{"1":2.07,"15":1.79,"5":1.91,"norm":{"1":0.0518,"15":0.0448,"5":0.0478}}}},"ecs.version":"1.6.0"}}
Aug 30 12:39:36 zeek1 filebeat[1043633]: {"log.level":"info","@timestamp":"2023-08-30T12:39:36.488Z","log.logger":"monitoring","log.origin":{"file.name":"log/log.go","file.line":187},"message":"Non-zero metrics in the last 30s","service.name":"filebeat","monitoring":{"metrics":{"beat":{"cgroup":{"memory":{"mem":{"usage":{"bytes":143130624}}}},"cpu":{"system":{"ticks":731000,"time":{"ms":590}},"total":{"ticks":10765650,"time":{"ms":8820},"value":10765650},"user":{"ticks":10034650,"time":{"ms":8230}}},"handles":{"limit":{"hard":524288,"soft":524288},"open":30},"info":{"ephemeral_id":"14379ec3-8426-41d1-9744-eb7d5f2c21db","uptime":{"ms":56100116},"version":"8.9.1"},"memstats":{"gc_next":124505088,"memory_alloc":96819056,"memory_total":638539168392,"rss":206356480},"runtime":{"goroutines":306}},"filebeat":{"events":{"active":737,"added":20403,"done":20996},"harvester":{"open_files":18,"running":18}},"libbeat":{"config":{"module":{"running":2}},"output":{"events":{"acked":20246,"active":50,"batches":411,"total":20246},"read":{"bytes":4520231},"write":{"bytes":37754237}},"pipeline":{"clients":38,"events":{"active":587,"published":20403,"total":20403},"queue":{"acked":20246}}},"registrar":{"states":{"current":20,"update":20246},"writes":{"success":21,"total":21}},"system":{"load":{"1":1.94,"15":1.79,"5":1.89,"norm":{"1":0.0485,"15":0.0448,"5":0.0473}}}},"ecs.version":"1.6.0"}}
Aug 30 12:40:06 zeek1 filebeat[1043633]: {"log.level":"info","@timestamp":"2023-08-30T12:40:06.484Z","log.logger":"monitoring","log.origin":{"file.name":"log/log.go","file.line":187},"message":"Non-zero metrics in the last 30s","service.name":"filebeat","monitoring":{"metrics":{"beat":{"cgroup":{"memory":{"mem":{"usage":{"bytes":156073984}}}},"cpu":{"system":{"ticks":731600,"time":{"ms":600}},"total":{"ticks":10773660,"time":{"ms":8010},"value":10773660},"user":{"ticks":10042060,"time":{"ms":7410}}},"handles":{"limit":{"hard":524288,"soft":524288},"open":30},"info":{"ephemeral_id":"14379ec3-8426-41d1-9744-eb7d5f2c21db","uptime":{"ms":56130113},"version":"8.9.1"},"memstats":{"gc_next":133026704,"memory_alloc":108850392,"memory_total":639039116664,"rss":219824128},"runtime":{"goroutines":306}},"filebeat":{"events":{"active":2407,"added":19065,"done":17395},"harvester":{"open_files":18,"running":18}},"libbeat":{"config":{"module":{"running":2}},"output":{"events":{"acked":18245,"active":50,"batches":371,"total":18245},"read":{"bytes":4073576},"write":{"bytes":33847492}},"pipeline":{"clients":38,"events":{"active":1407,"published":19065,"total":19065},"queue":{"acked":18245}}},"registrar":{"states":{"current":20,"update":18245},"writes":{"success":20,"total":20}},"system":{"load":{"1":2.26,"15":1.81,"5":1.95,"norm":{"1":0.0565,"15":0.0453,"5":0.0488}}}},"ecs.version":"1.6.0"}}
Aug 30 12:40:36 zeek1 filebeat[1043633]: {"log.level":"info","@timestamp":"2023-08-30T12:40:36.488Z","log.logger":"monitoring","log.origin":{"file.name":"log/log.go","file.line":187},"message":"Non-zero metrics in the last 30s","service.name":"filebeat","monitoring":{"metrics":{"beat":{"cgroup":{"memory":{"mem":{"usage":{"bytes":147886080}}}},"cpu":{"system":{"ticks":732210,"time":{"ms":610}},"total":{"ticks":10782570,"time":{"ms":8910},"value":10782570},"user":{"ticks":10050360,"time":{"ms":8300}}},"handles":{"limit":{"hard":524288,"soft":524288},"open":30},"info":{"ephemeral_id":"14379ec3-8426-41d1-9744-eb7d5f2c21db","uptime":{"ms":56160113},"version":"8.9.1"},"memstats":{"gc_next":130937392,"memory_alloc":104475392,"memory_total":639594475240,"rss":210587648},"runtime":{"goroutines":306}},"filebeat":{"events":{"active":1118,"added":21009,"done":22298},"harvester":{"open_files":18,"running":18}},"libbeat":{"config":{"module":{"running":2}},"output":{"events":{"acked":21498,"active":50,"batches":435,"total":21498},"read":{"bytes":4799563},"write":{"bytes":40041434}},"pipeline":{"clients":38,"events":{"active":918,"published":21009,"total":21009},"queue":{"acked":21498}}},"registrar":{"states":{"current":20,"update":21498},"writes":{"success":25,"total":25}},"system":{"load":{"1":2.22,"15":1.82,"5":1.97,"norm":{"1":0.0555,"15":0.0455,"5":0.0493}}}},"ecs.version":"1.6.0"}}
This file has been truncated. show original