Filebeats not shipping auth.log


(Dach) #1

Hi there,
Filebeat version = 1.1.2
Operating System = Ubuntu 12.04

The problem I'm having is that my auth.log is being sent to logstash server. It might be that the auth.log is owned by user "syslog" and group "adm" . I am getting some logs that is owned by root.

Here's are some debugging info:
2016/03/21 22:32:58.437095 reader.go:138: DBG End of file reached: /var/log/collectd.log; Backoff now.
2016/03/21 22:32:58.437274 reader.go:138: DBG End of file reached: /var/log/daemon.log; Backoff now.
2016/03/21 22:32:58.437674 reader.go:138: DBG End of file reached: /var/log/dpkg.log; Backoff now.
2016/03/21 22:32:58.438597 reader.go:138: DBG End of file reached: /var/log/mysql.log; Backoff now.
2016/03/21 22:32:58.438614 reader.go:138: DBG End of file reached: /var/log/mail.log; Backoff now.
2016/03/21 22:32:58.440852 reader.go:138: DBG End of file reached: /var/log/user.log; Backoff now.
2016/03/21 22:32:58.450325 reader.go:138: DBG End of file reached: /var/log/kern.log; Backoff now.
2016/03/21 22:32:59.436733 reader.go:138: DBG End of file reached: /var/log/collectd_logstash.log; Backoff now.
2016/03/21 22:32:59.437348 reader.go:138: DBG End of file reached: /var/log/collectd.log; Backoff now.
2016/03/21 22:33:01.436993 reader.go:138: DBG End of file reached: /var/log/collectd_logstash.log; Backoff now.
2016/03/21 22:33:01.437590 reader.go:138: DBG End of file reached: /var/log/collectd.log; Backoff now.
2016/03/21 22:33:02.436877 reader.go:138: DBG End of file reached: /var/log/consul.log; Backoff now.
2016/03/21 22:33:02.437021 util.go:20: DBG full line read
2016/03/21 22:33:02.437131 util.go:20: DBG full line read
2016/03/21 22:33:02.437214 reader.go:138: DBG End of file reached: /var/log/auth.log; Backoff now.
2016/03/21 22:33:02.437489 reader.go:138: DBG End of file reached: /var/log/daemon.log; Backoff now.
2016/03/21 22:33:02.437888 reader.go:138: DBG End of file reached: /var/log/dpkg.log; Backoff now.
2016/03/21 22:33:02.438857 reader.go:138: DBG End of file reached: /var/log/mysql.log; Backoff now.
2016/03/21 22:33:02.438860 reader.go:138: DBG End of file reached: /var/log/mail.log; Backoff now.


(Magnus B├Ąck) #2

What's your configuration (please format it as code so all indentation is preserved)? What does Filebeat's startup log look like?


(system) #3