Hi!
I've got a strange error:
[2017-12-21T20:54:31,450][WARN ][logstash.filters.grok ] Timeout executing grok '%{UNIXPATH:path}/(?[^]*)(?<fs_component>[-.0-9a-z]+)_(?<fs_logformat>[A-Z]+).logs' against field 'source' with value '/var/fairshell/logs/docker-apps/waf.data.log.error.log_demo-web_APACHE.logs'!
After that the filebeat-logstash is locked and logstash consumes 100% CPU (that stops when I stop filebeat and starts again when filebeat is restarted) and no other event from filebeat is treated by logstash. After some (long, sometimes 30) minutes Logstash seems to work again.
I checked with the grok debugger that the value is correctly parsed by the grok expression.
Hi,
I still get the error, but the 100% CPU problem has not come back (though i can't be sure if it's related):
[2017-12-22T13:23:33,145][WARN ][logstash.filters.grok ] Timeout executing grok '^%{UNIXPATH:path}/(?[^]*)(?<fs_component>[-.0-9a-z]+)_(?<fs_logformat>[A-Z]+).logs' against field 'source' with value '/var/fairshell/logs/docker-apps/waf.data.log.error.log_demo-web_APACHE.logs'!
Thanks!
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.