Hi all,
I'm new to ELK stack.
I'm trying to read the system error log, but i am unable to achieve. Here are my exploration.
SysErr Lof file sample:
[9/3/18 12:19:34:644 IST] 00000ff6 SystemErr R at org.apache.cxf.jaxrs.impl.ResponseBuilderImpl.status(ResponseBuilderImpl.java:78)
[9/3/18 12:19:34:645 IST] 00000ff6 SystemErr R at javax.ws.rs.core.Response.status(Response.java:613)
[9/3/18 12:19:34:645 IST] 00000ff6 SystemErr R at com.JavaAdapterResource.logout(JavaAdapterResource.java:1778)
[9/3/18 12:19:34:645 IST] 00000ff6 SystemErr R at sun.reflect.GeneratedMethodAccessor488.invoke(Unknown Source)
[9/3/18 12:19:34:645 IST] 00000ff6 SystemErr R at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:55)
[9/3/18 12:19:34:645 IST] 00000ff6 SystemErr R at java.lang.reflect.Method.invoke(Method.java:508)
[9/3/18 12:40:29:206 IST] 00001f17 SystemErr R java.lang.IllegalArgumentException: Illegal status value : 0
[9/3/18 12:41:02:344 IST] 00000ffc SystemErr R java.lang.IllegalArgumentException: Illegal status value : 0
[9/17/18 10:35:07:028 IST] 0000007b SystemErr R log4j:WARN No appenders could be found for logger (org.apache.cxf.common.logging.LogUtils).
[9/17/18 10:35:07:028 IST] 0000007b SystemErr R log4j:WARN Please initialize the log4j system properly.
[9/17/18 10:35:07:029 IST] 0000007b SystemErr R log4j:WARN See http://logging.apache.org/log4j/1.2/faq.html#noconfig for more info.
[9/17/18 15:09:47:415 IST] 0000007a SystemErr R Some product derivations are being skipped. For information about product derivation status, run:
java org.apache.openjpa.lib.conf.ProductDerivations
[9/17/18 15:09:47:416 IST] 0000007a SystemErr R com.ibm.ws.persistence.WsJpaProductDerivation:java.lang.ClassNotFoundException: com.ibm.ws.persistence.WsJpaProductDerivation
[9/17/18 15:09:47:463 IST] 0000007a SystemErr R 16 jpa-unit-rdbms WARN [server.startup : 0] openjpa.Runtime - Could not create the optional validation provider. Reason returned: "A default ValidatorFactory could not be created."
[9/17/18 15:09:48:038 IST] 0000007a SystemErr R 591 jpa-unit-rdbms INFO [server.startup : 0] openjpa.jdbc.JDBC - Using dictionary class "org.apache.openjpa.jdbc.sql.OracleDictionary" (Oracle Oracle Database 12c Enterprise Edition Release 12.1.0.2.0 - 64bit Production
With the Partitioning, OLAP, Advanced Analytics and Real Application Testing options ,Oracle JDBC driver 12.1.0.2.0).
[9/17/18 15:09:48:045 IST] 0000007a SystemErr R 598 jpa-unit-rdbms INFO [server.startup : 0] openjpa.jdbc.JDBC - Connected to Oracle version 12.12 using JDBC driver Oracle JDBC driver version 12.1.0.2.0.
[9/17/18 15:09:48:051 IST] 0000007a SystemErr R 604 jpa-unit-rdbms INFO [server.startup : 0] openjpa.Runtime - Starting OpenJPA 2.4.0
[9/17/18 15:09:49:883 IST] 0000007b SystemErr R Some product derivations are being skipped. For information about product derivation status, run:
java org.apache.openjpa.lib.conf.ProductDerivations
My Config file
input {
file{
path => "/app/install/database/SystemErr.log"
start_position => "beginning"
}
}
filter {
grok {
match =>
{
"message", "%{SYSLOG5424SD:time} %{NOTSPACE:id1} %{WORD:errortype}\s\s\s\s %{WORD:id2}\s%{WORD:check}"
}
}
if [check] == " " {
grok
{
match =>
{
"message", "%{WORD:id3} %{URIHOST}(%{JAVACLASS}:%{NUMBER:errorclass}) "
}
}
}
if [check] == "java.*" {
grok
{
match =>
{
"message", "%{URIHOST}:%{CISCO_REASON}:%{Number:statusvalue} "
}
}
}
if [check] == "log4j:*" {
grok
{
match =>
{
"message", "log4j:WARN %{CISCO_REASON} (%{URIHOST}). "
}
}
}
}
output {
stdout {}
elasticsearch{
hosts => "x.x.x.x"
index => "system_error_log_x"
}
}
Can anybody help me, how to read the entire log file. Please let me know my mistakes in log file.
Thanks in advance.