2018-06-12T15:28:57.243Z INFO instance/beat.go:468 Home path: [/usr/share/filebeat] Config path: [/etc/filebeat] Data path: [/var/lib/filebeat] Logs path: [/var/log/filebeat]
2018-06-12T15:28:57.245Z INFO instance/beat.go:475 Beat UUID: 18fe4e9b-e654-42b0-8d71-d4d2660307fd
2018-06-12T15:28:57.245Z INFO instance/beat.go:213 Setup Beat: filebeat; Version: 6.2.4
2018-06-12T15:28:57.248Z INFO add_cloud_metadata/add_cloud_metadata.go:301 add_cloud_metadata: hosting provider type detected as ec2, metadata={"availability_zone":"us-west-2c","instance_id":"i-0c8788050e301b03f","machine_type":"t2.small","provider":"ec2","region":"us-west-2"}
2018-06-12T15:28:57.249Z INFO elasticsearch/client.go:145 Elasticsearch url: URL
2018-06-12T15:28:57.249Z INFO pipeline/module.go:76 Beat name: NAME
2018-06-12T15:28:57.252Z INFO beater/filebeat.go:62 Enabled modules/filesets: apache2 (access, error), auditd (log), mysql (slowlog, error), nginx (access, error), system (auth, syslog), ()
2018-06-12T15:28:57.255Z INFO elasticsearch/client.go:145 Elasticsearch url: URL
2018-06-12T15:28:57.255Z INFO [monitoring] log/log.go:97 Starting metrics logging every 30s
2018-06-12T15:28:57.623Z INFO elasticsearch/client.go:690 Connected to Elasticsearch version 6.2.4
2018-06-12T15:28:57.623Z INFO kibana/client.go:69 Kibana url: URL
2018-06-12T15:29:25.953Z INFO instance/beat.go:583 Kibana dashboards successfully loaded.
2018-06-12T15:29:25.953Z INFO instance/beat.go:301 filebeat start running.
2018-06-12T15:29:25.953Z INFO registrar/registrar.go:110 Loading registrar data from /var/lib/filebeat/registry
2018-06-12T15:29:25.954Z INFO registrar/registrar.go:121 States Loaded from registrar: 9
2018-06-12T15:29:25.954Z INFO crawler/crawler.go:48 Loading Prospectors: 10
2018-06-12T15:29:25.958Z INFO log/prospector.go:111 Configured paths: [/var/log/*.log /var/log/custom_log/*/*.log]
2018-06-12T15:29:25.958Z INFO log/prospector.go:111 Configured paths: [/var/log/apache2/access.log* /var/log/apache2/other_vhosts_access.log*]
2018-06-12T15:29:25.958Z INFO log/prospector.go:111 Configured paths: [/var/log/apache2/error.log*]
2018-06-12T15:29:25.959Z INFO log/prospector.go:111 Configured paths: [/var/log/audit/audit.log*]
2018-06-12T15:29:25.960Z INFO log/prospector.go:111 Configured paths: [/var/log/mysql/error.log* /var/log/mysqld.log*]
2018-06-12T15:29:25.960Z INFO log/prospector.go:111 Configured paths: [/var/log/mysql/mysql-slow.log* /var/lib/mysql/mssynclog-slow.log]
2018-06-12T15:29:25.960Z INFO log/prospector.go:111 Configured paths: [/var/log/nginx/access.log*]
2018-06-12T15:29:25.961Z INFO log/prospector.go:111 Configured paths: [/var/log/nginx/error.log*]
2018-06-12T15:29:25.964Z INFO log/prospector.go:111 Configured paths: [/var/log/auth.log* /var/log/secure*]
2018-06-12T15:29:25.965Z INFO log/prospector.go:111 Configured paths: [/var/log/messages* /var/log/syslog*]
2018-06-12T15:29:25.965Z INFO crawler/crawler.go:82 Loading and starting Prospectors completed. Enabled prospectors: 10
2018-06-12T15:29:25.965Z INFO cfgfile/reload.go:127 Config reloader started
2018-06-12T15:29:25.966Z INFO cfgfile/reload.go:219 Loading of config files completed.
2018-06-12T15:29:25.967Z INFO log/harvester.go:216 Harvester started for file: /var/log/custom_log/rkym/access.log
2018-06-12T15:29:25.968Z INFO log/harvester.go:216 Harvester started for file: /var/log/audit/audit.log
2018-06-12T15:29:25.994Z INFO log/harvester.go:216 Harvester started for file: /var/log/secure
2018-06-12T15:29:26.017Z INFO log/harvester.go:216 Harvester started for file: /var/log/messages
2018-06-12T15:29:26.075Z INFO log/harvester.go:216 Harvester started for file: /var/log/custom_log/rkym/error.log
2018-06-12T15:29:26.078Z INFO log/harvester.go:216 Harvester started for file: /var/log/secure-20180610
2018-06-12T15:29:26.079Z INFO log/harvester.go:216 Harvester started for file: /var/log/messages-20180610
2018-06-12T15:29:26.397Z INFO elasticsearch/client.go:690 Connected to Elasticsearch version 6.2.4
2018-06-12T15:29:26.484Z INFO template/load.go:73 Template already exists and will not be overwritten.
2018-06-12T15:29:27.257Z INFO [monitoring] log/log.go:124 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":30,"time":34},"total":{"ticks":250,"time":254,"value":250},"user":{"ticks":220,"time":220}},"info":{"ephemeral_id":"2afd8c1a-c4fc-44b9-b78e-d8cedd3f70eb","uptime":{"ms":30018}},"memstats":{"gc_next":25618576,"memory_alloc":15300696,"memory_total":44044832,"rss":33746944}},"filebeat":{"events":{"active":4123,"added":4139,"done":16},"harvester":{"open_files":7,"running":7,"started":7},"prospector":{"log":{"files":{"truncated":2}}}},"libbeat":{"config":{"module":{"running":0},"reloads":1},"output":{"read":{"bytes":9979},"type":"elasticsearch","write":{"bytes":3156}},"pipeline":{"clients":10,"events":{"active":4120,"filtered":16,"published":4116,"total":4136}}},"registrar":{"states":{"current":11,"update":16},"writes":16},"system":{"cpu":{"cores":1},"load":{"1":0,"15":0.05,"5":0.01,"norm":{"1":0,"15":0.05,"5":0.01}}}}}}
2018-06-12T15:29:57.256Z INFO [monitoring] log/log.go:124 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":170,"time":177},"total":{"ticks":1230,"time":1239,"value":1230},"user":{"ticks":1060,"time":1062}},"info":{"ephemeral_id":"2afd8c1a-c4fc-44b9-b78e-d8cedd3f70eb","uptime":{"ms":60018}},"memstats":{"gc_next":25811952,"memory_alloc":14634728,"memory_total":198267504,"rss":24649728}},"filebeat":{"events":{"active":-4123,"added":28641,"done":32764},"harvester":{"open_files":7,"running":7}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":12393,"batches":249,"total":12393},"read":{"bytes":230644},"write":{"bytes":9727859}},"pipeline":{"clients":10,"events":{"active":0,"filtered":20371,"published":8277,"retry":50,"total":28644},"queue":{"acked":12393}}},"registrar":{"states":{"current":11,"update":32764},"writes":248},"system":{"load":{"1":0.13,"15":0.05,"5":0.05,"norm":{"1":0.13,"15":0.05,"5":0.05}}}}}}