# Error running input: error receiving slowlog data: ERR unknown command \`SLOWLOG\`, with args beginning with: \`GET\`

**URL:** <https://discuss.elastic.co/t/error-running-input-error-receiving-slowlog-data-err-unknown-command-slowlog-with-args-beginning-with-get/246826>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 28, 2020, 11:36pm UTC](https://discuss.elastic.co/t/error-running-input-error-receiving-slowlog-data-err-unknown-command-slowlog-with-args-beginning-with-get/246826 "2020-08-28T23:36:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![fzyzcjy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fzyzcjy/32/78628_2.png) [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Post date:** [August 28, 2020, 11:36pm UTC](https://discuss.elastic.co/t/error-running-input-error-receiving-slowlog-data-err-unknown-command-slowlog-with-args-beginning-with-get/246826/1 "2020-08-28T23:36:35Z")

</div>

Hi I am using redis filebeat with the following config. However the error Error running input: error receiving slowlog data: ERR unknown command `SLOWLOG`, with args beginning with: `GET` occurs very frequently.

Thanks for any suggestions!

```auto
# ref: https://github.com/elastic/cloud-on-k8s/blob/master/config/recipes/beats/filebeat_autodiscover.yaml
apiVersion: beat.k8s.elastic.co/v1beta1
kind: Beat
metadata:
  name: {{ include "elastic.name.beat.filebeat" . }}
  labels: {{- include "elastic.labels" . | nindent 4 }}
spec:
  type: filebeat
  version: {{ .Values.filebeat.version }}
  image: "elastic/filebeat:{{ .Values.filebeat.version }}"
  elasticsearchRef:
    name: {{ include "elastic.name.elasticsearch" . }}
  kibanaRef:
    name: {{ include "elastic.name.kibana" . }}
  config:
    filebeat:
      autodiscover:
        providers:
          - type: kubernetes
            host: ${HOSTNAME}
            include_annotations:
              - tom_filebeat_mode
            hints:
              enabled: true
              default_config:
                type: container
                paths:
                  - /var/log/containers/*${data.kubernetes.container.id}.log
            templates:
              {{- range $k, $v := .Values.filebeat.redis.modeSentinel }}
              - condition:
                  equals:
                    kubernetes.annotations.tom_filebeat_mode: {{ $v.release }}
                config:
                  # https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-redis.html
                  # and https://discuss.elastic.co/t/redis-slowlog-monitoring-with-eck-elastic-on-kubernetes/246377/2
                  - module: redis
                    log:
                      enabled: true
                      var.paths: ["/var/log/containers/*${data.kubernetes.container.id}.log"]
                    slowlog:
                      enabled: true
                      var.hosts: ["${data.host}:${data.kubernetes.annotations.redis_port}"]
                      # https://www.elastic.co/blog/securely-manage-credentials-monitoring-kubernetes-workloads-autodiscovery
                      var.password: "this_is_a_password"
{{/* var.password: "${kubernetes.{{ $.Release.Namespace }}.{{ $v.release }}.redis-password}"*/}}
              {{- end }}

...

```

That part actually expands to the following (got by reading the spec of the CRD in k8s)

```auto
spec:
  config:
    filebeat:
      autodiscover:
        providers:
          - hints:
              default_config:
                paths:
                  - '/var/log/containers/*${data.kubernetes.container.id}.log'
                type: container
              enabled: true
            host: '${HOSTNAME}'
            include_annotations:
              - tom_filebeat_mode
            templates:
              - condition:
                  equals:
                    kubernetes.annotations.tom_filebeat_mode: tom-redis-cache
                config:
                  - log:
                      enabled: true
                      var.paths:
                        - >-
                          /var/log/containers/*${data.kubernetes.container.id}.log
                    module: redis
                    slowlog:
                      enabled: true
                      var.hosts:
                        - '${data.host}:${data.kubernetes.annotations.redis_port}'
                      var.password: '${kubernetes.default.tom-redis-cache.redis-password}'
              - condition:
                  equals:
                    kubernetes.annotations.tom_filebeat_mode: tom-redis-custom-code
                config:
                  - log:
                      enabled: true
                      var.paths:
                        - >-
                          /var/log/containers/*${data.kubernetes.container.id}.log
                    module: redis
                    slowlog:
                      enabled: true
                      var.hosts:
                        - '${data.host}:${data.kubernetes.annotations.redis_port}'
                      var.password: >-
                        ${kubernetes.default.tom-redis-custom-code.redis-password}
              - condition:
                  equals:
                    kubernetes.annotations.tom_filebeat_mode: tom-redis-bloom
                config:
                  - log:
                      enabled: true
                      var.paths:
                        - >-
                          /var/log/containers/*${data.kubernetes.container.id}.log
                    module: redis
                    slowlog:
                      enabled: true
                      var.hosts:
                        - '${data.host}:${data.kubernetes.annotations.redis_port}'
                      var.password: '${kubernetes.default.tom-redis-bloom.redis-password}'
            type: kubernetes
...

```

---

<div class="post-metadata">

**Author:** ![fzyzcjy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fzyzcjy/32/78628_2.png) [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Post date:** [August 28, 2020, 11:52pm UTC](https://discuss.elastic.co/t/error-running-input-error-receiving-slowlog-data-err-unknown-command-slowlog-with-args-beginning-with-get/246826/2 "2020-08-28T23:52:05Z")

</div>

Oh I find the reason: I also try to get slowlog for _sentinels_... But they do not support this. Only master/replica supports SLOWLOG command.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 26, 2020, 1:52am UTC](https://discuss.elastic.co/t/error-running-input-error-receiving-slowlog-data-err-unknown-command-slowlog-with-args-beginning-with-get/246826/3 "2020-09-26T01:52:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
