When set 'sincedb_path' to '/dev/null' and 'start_position' to 'beginning', logstash does not parse files as expected, it always start and hangs at output below:
Settings: Default pipeline workers: 4
Pipeline main started
in my case, I have a lot of existing logs, but I do not want logstash to monitoring the logs, I just want the logs to be parsed and sent to elastic search and be done with them. In addition, the logs are stored in a external hard drive formatted with NTFS filesystem mounted to Ubuntu.
heres my log.conf for testing on a single log file:
the "www.placeholder.com" is missing. therefore In order to get the domain name this log is relevant to, I need to use the file plugin and mutate the path of the file into domain name field in my index,
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.