2019-10-31T13:03:13.173Z INFO instance/beat.go:607 Home path: [/usr/share/filebeat] Config path: [/usr/share/filebeat] Data path: [/usr/share/filebeat/data] Logs path: [/usr/share/filebeat/logs]
2019-10-31T13:03:13.196Z INFO instance/beat.go:615 Beat ID: 90602ca9-90f9-4372-a0fc-4205ad22a900
2019-10-31T13:03:13.197Z INFO [seccomp] seccomp/seccomp.go:124 Syscall filter successfully installed
2019-10-31T13:03:13.197Z INFO [beat] instance/beat.go:903 Beat info {"system_info": {"beat": {"path": {"config": "/usr/share/filebeat", "data": "/usr/share/filebeat/data", "home": "/usr/share/filebeat", "logs": "/usr/share/filebeat/logs"}, "type": "filebeat", "uuid": "90602ca9-90f9-4372-a0fc-4205ad22a900"}}}
2019-10-31T13:03:13.198Z INFO [beat] instance/beat.go:912 Build info {"system_info": {"build": {"commit": "12ee6cd05c1bfdc69721ddab1f473417b1514576", "libbeat": "7.4.1", "time": "2019-10-22T16:22:37.000Z", "version": "7.4.1"}}}
2019-10-31T13:03:13.198Z INFO [beat] instance/beat.go:915 Go runtime info {"system_info": {"go": {"os":"linux","arch":"amd64","max_procs":2,"version":"go1.12.9"}}}
2019-10-31T13:03:13.205Z INFO [beat] instance/beat.go:919 Host info {"system_info": {"host": {"architecture":"x86_64","boot_time":"2019-04-03T12:20:50Z","containerized":true,"name":"749cfd1a167e","ip":["127.0.0.1/8","172.17.0.2/16"],"kernel_version":"4.15.0-46-generic","mac":["02:42:ac:11:00:02"],"os":{"family":"redhat","platform":"centos","name":"CentOS Linux","version":"7 (Core)","major":7,"minor":6,"patch":1810,"codename":"Core"},"timezone":"UTC","timezone_offset_sec":0}}}
2019-10-31T13:03:13.205Z INFO [beat] instance/beat.go:948 Process info {"system_info": {"process": {"capabilities": {"inheritable":["chown","dac_override","fowner","fsetid","kill","setgid","setuid","setpcap","net_bind_service","net_raw","sys_chroot","mknod","audit_write","setfcap"],"permitted":["chown","dac_override","fowner","fsetid","kill","setgid","setuid","setpcap","net_bind_service","net_raw","sys_chroot","mknod","audit_write","setfcap"],"effective":["chown","dac_override","fowner","fsetid","kill","setgid","setuid","setpcap","net_bind_service","net_raw","sys_chroot","mknod","audit_write","setfcap"],"bounding":["chown","dac_override","fowner","fsetid","kill","setgid","setuid","setpcap","net_bind_service","net_raw","sys_chroot","mknod","audit_write","setfcap"],"ambient":null}, "cwd": "/usr/share/filebeat", "exe": "/usr/share/filebeat/filebeat", "name": "filebeat", "pid": 1, "ppid": 0, "seccomp": {"mode":"filter","no_new_privs":true}, "start_time": "2019-10-31T13:03:07.350Z"}}}
2019-10-31T13:03:13.205Z INFO instance/beat.go:292 Setup Beat: filebeat; Version: 7.4.1
2019-10-31T13:03:13.209Z INFO [publisher] pipeline/module.go:97 Beat name: 749cfd1a167e
2019-10-31T13:03:13.241Z WARN beater/filebeat.go:152 Filebeat is unable to load the Ingest Node pipelines for the configured modules because the Elasticsearch output is not configured/enabled. If you have already loaded the Ingest Node pipelines or are using Logstash pipelines, you can ignore this warning.
2019-10-31T13:03:13.242Z INFO instance/beat.go:422 filebeat start running.
2019-10-31T13:03:13.242Z INFO registrar/migrate.go:104 No registry home found. Create: /usr/share/filebeat/data/registry/filebeat
2019-10-31T13:03:13.242Z INFO registrar/migrate.go:112 Initialize registry meta file
2019-10-31T13:03:13.243Z INFO [monitoring] log/log.go:118 Starting metrics logging every 30s
2019-10-31T13:03:13.300Z INFO registrar/registrar.go:108 No registry file found under: /usr/share/filebeat/data/registry/filebeat/data.json. Creating a new registry file.
2019-10-31T13:03:13.304Z INFO registrar/registrar.go:145 Loading registrar data from /usr/share/filebeat/data/registry/filebeat/data.json
2019-10-31T13:03:13.304Z INFO registrar/registrar.go:152 States Loaded from registrar: 0
2019-10-31T13:03:13.304Z WARN beater/filebeat.go:368 Filebeat is unable to load the Ingest Node pipelines for the configured modules because the Elasticsearch output is not configured/enabled. If you have already loaded the Ingest Node pipelines or are using Logstash pipelines, you can ignore this warning.
2019-10-31T13:03:13.304Z INFO crawler/crawler.go:72 Loading Inputs: 1
2019-10-31T13:03:13.306Z INFO log/input.go:152 Configured paths: [/var/www/vhosts/domain.tld/shared/storage/logs/audit-log.log]
2019-10-31T13:03:13.307Z INFO input/input.go:114 Starting input of type: log; ID: 16756111730527578735
2019-10-31T13:03:13.307Z INFO crawler/crawler.go:106 Loading and starting Inputs completed. Enabled inputs: 1
2019-10-31T13:03:13.317Z INFO log/harvester.go:251 Harvester started for file: /var/www/vhosts/domain.tld/shared/storage/logs/audit-log.log
2019-10-31T13:03:14.318Z INFO pipeline/output.go:95 Connecting to backoff(async(tcp://[MY-ELK-IPv6-ADDRESS]:5044))
2019-10-31T13:03:15.477Z ERROR pipeline/output.go:100 Failed to connect to backoff(async(tcp://[MY-ELK-IPv6-ADDRESS]:5044)): dial tcp [MY-ELK-IPv6-ADDRESS]:5044: connect: cannot assign requested address
2019-10-31T13:03:15.478Z INFO pipeline/output.go:93 Attempting to reconnect to backoff(async(tcp://[MY-ELK-IPv6-ADDRESS]:5044)) with 1 reconnect attempt(s)
2019-10-31T13:03:18.915Z ERROR pipeline/output.go:100 Failed to connect to backoff(async(tcp://[MY-ELK-IPv6-ADDRESS]:5044)): dial tcp [MY-ELK-IPv6-ADDRESS]:5044: connect: cannot assign requested address
2019-10-31T13:03:18.915Z INFO pipeline/output.go:93 Attempting to reconnect to backoff(async(tcp://[MY-ELK-IPv6-ADDRESS]:5044)) with 2 reconnect attempt(s)
2019-10-31T13:03:24.731Z ERROR pipeline/output.go:100 Failed to connect to backoff(async(tcp://[MY-ELK-IPv6-ADDRESS]:5044)): dial tcp [MY-ELK-IPv6-ADDRESS]:5044: connect: cannot assign requested address
2019-10-31T13:03:24.731Z INFO pipeline/output.go:93 Attempting to reconnect to backoff(async(tcp://[MY-ELK-IPv6-ADDRESS]:5044)) with 3 reconnect attempt(s)
2019-10-31T13:03:33.457Z ERROR pipeline/output.go:100 Failed to connect to backoff(async(tcp://[MY-ELK-IPv6-ADDRESS]:5044)): dial tcp [MY-ELK-IPv6-ADDRESS]:5044: connect: cannot assign requested address
2019-10-31T13:03:33.457Z INFO pipeline/output.go:93 Attempting to reconnect to backoff(async(tcp://[MY-ELK-IPv6-ADDRESS]:5044)) with 4 reconnect attempt(s)