Hi Badger,
I am unaware about the location where to fetch the logs.
I generally see the logs on the console when i run the below command
/usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/csv-read-3.conf
I have invoked the command line to get the verbose/debug level logs as well. However if these are not the ones you are expecting pl guide to locate the same so that I can fetch them as well
Sample data o/p is given below, (if this may help)
{
"@timestamp" => 2022-02-07T19:40:00.488Z,
"No." => "48789",
"method" => "",
"HTTP_Header_Status" => "200",
"Stream_Identifier" => "246505,246505",
"Length" => "222",
"String value" => "AUTHENTICATION_SUCCESS,4F8B776A1ADD57CB2612E550FA503F622B8DCF484D0498613DA8E6B08837AC20",
"Time" => "2022-02-07 19:40:00.488173",
"Destination" => "10.242.14.143",
"Source" => "10.242.21.25",
"Info" => "[TCP Spurious Retransmission] , HEADERS[246505]: 200 OK, DATA[246505], JavaScript Object Notation (application/json)",
"Protocol" => "HTTP2/JSON",
"Service" => "%{[:path][1]}",
"Service_Request" => "",
"Key" => "authResult,kseaf"
}
{
"@timestamp" => 2022-02-07T19:40:00.538Z,
"No." => "48790",
"method" => "",
"HTTP_Header_Status" => "",
"Stream_Identifier" => "1399597,1399597",
"Length" => "458",
"String value" => "4742c3ce-87f7-42d9-8d5e-75ac7d6e43e4,imeisv-3506355824625301,HOMOGENEOUS_SUPPORT,http://10.242.14.150:8080/nudm-uecm/v1.0.2/imsi-525055000090149/registrations/amf-3gpp-access/notification,525,05,010069,NR",
"Time" => "2022-02-07 19:40:00.538474",
"Destination" => "10.242.21.20",
"Source" => "10.242.14.141",
"Info" => "HEADERS[1399597], DATA[1399597], JavaScript Object Notation",
"Protocol" => "HTTP2/JSON",
"Service" => "nudm-uecm",
"Service_Request" => "/nudm-uecm/v1/imsi-525055000090149/registrations/amf-3gpp-access",
"Key" => "amfInstanceId,pei,imsVoPs,deregCallbackUri,mcc,mnc,plmnId,amfId,guami,ratType"