I running FileBeat on Windows and LogStash on Linux.
When I'm sending a log file from FileBeat to LogStash ... LogStash is getting in utf8 and the grok filtering is not working. But when I'm sending the file from the linux system using the nc command, Logstash is getting in ASCII and everything is working well.
I'm not sure what you mean here. Does your log file contain any bytes with the eight bit set, i.e. an ASCII value >127? If yes then it's not ASCII. If no then there's no difference between the ASCII representation of the text and the UTF-8 representation of the same text.
We don't need the whole log. A single line that exhibits the problem you describe will do. Make sure you format it as preformatted text when posting. The same line fed through hexdump -C could also be useful.
And the line sent is:
DEBUG 2017-01-25 22:48:40,185 class:Gateways_JsonPostGW topic:null method:OnLoad server:IP-0A0001F8 ip:10.0.2.5 reqid:ff35f8a6-7135-4359-ac97-4e97da04b7a3 partner:436 action:GetMediaInfo uid:0 msg:API Request -
I have got Chinese character and it's still not working:
[2017-02-01T15:37:14,622][DEBUG][logstash.pipeline ] filter received {"event"=>{"@timestamp"=>2017-02-01T15:37:14.613Z, "port"=>64109, "@version"=>"1", "host"=>"52.19.166.128", "message"=>"㉗\u0000\u0001㉃\u0000ŷ硞泐八�【߰衻뚌摛煲俭�ᙒ㨖웆怘쳅㺻˛刭㦥葼蟑瑻嫟\u0E8E믿뭟굖㞫헍�踜ꦥ䢀枈⾞ǡ㧔菫ↁ⍓҄츎籤詰䧠㛚酃ꓑ͂ꙴ⥕⚕ﺮ෦ᦚ䶪췺ᜤნ㈷꿋㹢唽렾哕ꦨ畕얓꿉�次쥛嚶籜充뢆몮ଜdz㰯쫤㾓鷼ያ뿒랉酃ꃾ\u1AF6辝硣榙ᦑ敘沰傉�ᣑఔˮ⣲㎽蓺㺸䋜ﴔ텹�ಃᠹ㺺ᚿ丏蹚ᅸ㻱賻荔睊⧽礣걇굒镦ꤑ㌿�ᚻ⸷�蛖닔릑䕮뚒驭⤋�阭ꧢ塒⸼쵱譼ⶨ觖\u4DB8蕛䯻ꥳ抱\u2D2Aㆆữ\u0E7B鼖๑䡈稼썄跖쭿ᙈ藸滣쑳끮Ȅ鏪㒃쯥伀\u0000\uFFFF席飊"}}
[2017-02-01T15:37:14,624][DEBUG][logstash.filters.grok ] Running grok filter {:event=>2017-02-01T15:37:14.613Z 52.19.166.128 ㉗㉃ŷ硞泐八�【߰衻뚌摛煲俭�ᙒ㨖웆怘쳅㺻˛刭㦥葼蟑瑻嫟ຎ믿뭟굖㞫헍�踜ꦥ䢀枈⾞ǡ㧔菫ↁ⍓҄츎籤詰䧠㛚酃ꓑ͂ꙴ⥕⚕ﺮ෦ᦚ䶪췺ᜤნ㈷꿋㹢唽렾哕ꦨ畕얓꿉�次쥛嚶籜充뢆몮ଜdz㰯쫤㾓鷼ያ뿒랉酃ꃾ辝硣榙ᦑ敘沰傉�ᣑఔˮ⣲㎽蓺㺸䋜ﴔ텹�ಃᠹ㺺ᚿ丏蹚ᅸ㻱賻荔睊⧽礣걇굒镦ꤑ㌿�ᚻ⸷�蛖닔릑䕮뚒驭⤋�阭ꧢ塒⸼쵱譼ⶨ觖䶸蕛䯻ꥳ抱ㆆữ鼖๑䡈稼썄跖쭿ᙈ藸滣쑳끮Ȅ鏪㒃쯥伀▒席飊}
[2017-02-01T15:37:14,628][DEBUG][logstash.filters.grok ] Event now: {:event=>2017-02-01T15:37:14.613Z 52.19.166.128 ㉗㉃ŷ硞泐八�【߰衻뚌摛煲俭�ᙒ㨖웆怘쳅㺻˛刭㦥葼蟑瑻嫟ຎ믿뭟굖㞫헍�踜ꦥ䢀枈⾞ǡ㧔菫ↁ⍓҄츎籤詰䧠㛚酃ꓑ͂ꙴ⥕⚕ﺮ෦ᦚ䶪췺ᜤნ㈷꿋㹢唽렾哕ꦨ畕얓꿉�次쥛嚶籜充뢆몮ଜdz㰯쫤㾓鷼ያ뿒랉酃ꃾ辝硣榙ᦑ敘沰傉�ᣑఔˮ⣲㎽蓺㺸䋜ﴔ텹�ಃᠹ㺺ᚿ丏蹚ᅸ㻱賻荔睊⧽礣걇굒镦ꤑ㌿�ᚻ⸷�蛖닔릑䕮뚒驭⤋�阭ꧢ塒⸼쵱譼ⶨ觖䶸蕛䯻ꥳ抱ㆆữ鼖๑䡈稼썄跖쭿ᙈ藸滣쑳끮Ȅ鏪㒃쯥伀▒席飊}
[2017-02-01T15:37:14,634][DEBUG][logstash.pipeline ] output received {"event"=>{"@timestamp"=>2017-02-01T15:37:14.613Z, "port"=>64109, "@version"=>"1", "host"=>"52.19.166.128", "message"=>"㉗\u0000\u0001㉃\u0000ŷ硞泐八�【߰衻뚌摛煲俭�ᙒ㨖웆怘쳅㺻˛刭㦥葼蟑瑻嫟\u0E8E믿뭟굖㞫헍�踜ꦥ䢀枈⾞ǡ㧔菫ↁ⍓҄츎籤詰䧠㛚酃ꓑ͂ꙴ⥕⚕ﺮ෦ᦚ䶪췺ᜤნ㈷꿋㹢唽렾哕ꦨ畕얓꿉�次쥛嚶籜充뢆몮ଜdz㰯쫤㾓鷼ያ뿒랉酃ꃾ\u1AF6辝硣榙ᦑ敘沰傉�ᣑఔˮ⣲㎽蓺㺸䋜ﴔ텹�ಃᠹ㺺ᚿ丏蹚ᅸ㻱賻荔睊⧽礣걇굒镦ꤑ㌿�ᚻ⸷�蛖닔릑䕮뚒驭⤋�阭ꧢ塒⸼쵱譼ⶨ觖\u4DB8蕛䯻ꥳ抱\u2D2Aㆆữ\u0E7B鼖๑䡈稼썄跖쭿ᙈ藸滣쑳끮Ȅ鏪㒃쯥伀\u0000\uFFFF席飊", "tags"=>["_grokparsefailure"]}}
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.