Please share me the filebeat.yml and "/etc/filebeat/modules/system.yml" config files;
As you mentioned you are good with system modules, just wanted to compare the config files. I have not made changes to config file. Just made an entry[ var.convert_timezone: true] change to /etc/filebeat/modules/system.yml
- module: system
# Syslog
syslog:
enabled: true
# Set custom paths for the log files. If left empty,
# Filebeat will choose the paths depending on your OS.
#var.paths:
# Convert the timestamp to UTC. Requires Elasticsearch >= 6.1.
var.convert_timezone: true
# Authorization logs
auth:
enabled: true
# Set custom paths for the log files. If left empty,
# Filebeat will choose the paths depending on your OS.
#var.paths:
# Convert the timestamp to UTC. Requires Elasticsearch >= 6.1.
var.convert_timezone: true
File: /var/lib/filebeat/registry
[{"source":"/var/log/fontconfig.log","offset":1595,"timestamp":"2018-07-27T04:39:33.039794035-07:00","ttl":-1,"type":"log","meta":null,"FileStateOS":{"inode":55457,"device":51713}},{"source":"/var/log/kern.log","offset":0,"timestamp":"2018-07-27T04:39:33.043196589-07:00","ttl":-1,"type":"log","meta":null,"FileStateOS":{"inode":6554,"device":51713}},{"source":"/var/log/mail.log","offset":0,"timestamp":"2018-07-27T04:39:33.046297732-07:00","ttl":-1,"type":"log","meta":null,"FileStateOS":{"inode":6542,"device":51713}},{"source":"/var/log/alternatives.log","offset":0,"timestamp":"2018-07-27T04:39:33.049354647-07:00","ttl":-1,"type":"log","meta":null,"FileStateOS":{"inode":6560,"device":51713}},{"source":"/var/log/cloud-init-output.log","offset":1830858,"timestamp":"2018-07-27T04:39:33.052581509-07:00","ttl":-1,"type":"log","meta":null,"FileStateOS":{"inode":51060,"device":51713}},{"source":"/var/log/cloud-init.log","offset":255061,"timestamp":"2018-07-27T04:39:33.055793968-07:00","ttl":-1,"type":"log","meta":null,"FileStateOS":{"inode":51059,"device":51713}},{"source":"/var/log/dpkg.log","offset":33763,"timestamp":"2018-07-27T04:39:33.059004416-07:00","ttl":-1,"type":"log","meta":null,"FileStateOS":{"inode":6556,"device":51713}},{"source":"/var/log/auth.log","offset":195840,"timestamp":"2018-07-27T04:39:33.131430975-07:00","ttl":-1,"type":"log","meta":null,"FileStateOS":{"inode":5317,"device":51713}},{"source":"/var/log/syslog.1","offset":498236,"timestamp":"2018-07-27T04:39:33.145264877-07:00","ttl":-1,"type":"log","meta":null,"FileStateOS":{"inode":4955,"device":51713}},{"source":"/var/log/syslog","offset":95634,"timestamp":"2018-07-27T04:39:33.149061775-07:00","ttl":-1,"type":"log","meta":null,"FileStateOS":{"inode":4185,"device":51713}},{"source":"/var/log/ansible.log","offset":1524521,"timestamp":"2018-07-27T04:39:33.065642651-07:00","ttl":-1,"type":"log","meta":null,"FileStateOS":{"inode":51200,"device":51713}},{"source":"/var/log/aptitude","offset":0,"timestamp":"2018-07-14T07:30:40.4573387-07:00","ttl":-2,"type":"log","meta":null,"FileStateOS":{"inode":6552,"device":51713}},{"source":"/var/log/auth.log.1","offset":0,"timestamp":"2018-07-27T04:39:33.135059822-07:00","ttl":-1,"type":"log","meta":null,"FileStateOS":{"inode":5316,"device":51713}},{"source":"/var/log/syslog.7.gz","offset":23413,"timestamp":"2018-07-27T03:36:26.344859976-07:00","ttl":-2,"type":"log","meta":null,"FileStateOS":{"inode":4590,"device":51713}},{"source":"/var/log/syslog.2.gz","offset":22455,"timestamp":"2018-07-27T03:36:26.35104531-07:00","ttl":-2,"type":"log","meta":null,"FileStateOS":{"inode":4895,"device":51713}},{"source":"/var/log/syslog.3.gz","offset":23457,"timestamp":"2018-07-27T03:36:26.331978977-07:00","ttl":-2,"type":"log","meta":null,"FileStateOS":{"inode":6436,"device":51713}},{"source":"/var/log/syslog.4.gz","offset":23302,"timestamp":"2018-07-27T03:36:26.334868819-07:00","ttl":-2,"type":"log","meta":null,"FileStateOS":{"inode":5535,"device":51713}},{"source":"/var/log/syslog.5.gz","offset":23858,"timestamp":"2018-07-27T03:36:26.338248729-07:00","ttl":-2,"type":"log","meta":null,"FileStateOS":{"inode":2967,"device":51713}},{"source":"/var/log/syslog.6.gz","offset":24364,"timestamp":"2018-07-27T03:36:26.341475422-07:00","ttl":-2,"type":"log","meta":null,"FileStateOS":{"inode":2788,"device":51713}},{"source":"/var/log/alternatives.log","offset":0,"timestamp":"2018-07-27T04:39:33.068791974-07:00","ttl":-1,"type":"log","meta":{},"FileStateOS":{"inode":6560,"device":51713}},{"source":"/var/log/fontconfig.log","offset":1595,"timestamp":"2018-07-27T04:39:33.072163462-07:00","ttl":-1,"type":"log","meta":{},"FileStateOS":{"inode":55457,"device":51713}},{"source":"/var/log/mail.log","offset":0,"timestamp":"2018-07-27T04:39:33.075215686-07:00","ttl":-1,"type":"log","meta":{},"FileStateOS":{"inode":6542,"device":51713}},{"source":"/var/log/cloud-init.log","offset":255061,"timestamp":"2018-07-27T04:39:33.078431985-07:00","ttl":-1,"type":"log","meta":{},"FileStateOS":{"inode":51059,"device":51713}},{"source":"/var/log/dpkg.log","offset":33763,"timestamp":"2018-07-27T04:39:33.081763426-07:00","ttl":-1,"type":"log","meta":{},"FileStateOS":{"inode":6556,"device":51713}},{"source":"/var/log/kern.log","offset":0,"timestamp":"2018-07-27T04:39:33.085154411-07:00","ttl":-1,"type":"log","meta":{},"FileStateOS":{"inode":6554,"device":51713}},{"source":"/var/log/ansible.log","offset":1524521,"timestamp":"2018-07-27T04:39:33.090848975-07:00","ttl":-1,"type":"log","meta":{},"FileStateOS":{"inode":51200,"device":51713}},{"source":"/var/log/auth.log","offset":198711,"timestamp":"2018-07-27T04:39:33.216345544-07:00","ttl":-1,"type":"log","meta":{},"FileStateOS":{"inode":5317,"device":51713}},{"source":"/var/log/cloud-init-output.log","offset":1830858,"timestamp":"2018-07-27T04:39:33.097910848-07:00","ttl":-1,"type":"log","meta":{},"FileStateOS":{"inode":51060,"device":51713}},{"source":"/var/log/syslog","offset":0,"timestamp":"2018-07-27T04:39:33.194075037-07:00","ttl":-1,"type":"log","meta":{},"FileStateOS":{"inode":4185,"device":51713}},{"source":"/var/log/syslog.1","offset":0,"timestamp":"2018-07-27T04:39:33.204599189-07:00","ttl":-1,"type":"log","meta":{},"FileStateOS":{"inode":4955,"device":51713}},{"source":"/var/log/auth.log.1","offset":0,"timestamp":"2018-07-27T04:39:33.230591066-07:00","ttl":-1,"type":"log","meta":{},"FileStateOS":{"inode":5316,"device":51713}}]
Thanks