Could you help me please to figure out what is going on?
Packetbeat returns http.response 404 for existing files.
But in the same time when I check it manually with CURL it returns 200
packetbeat version 5.6.4
elasticsearch version 5.5.2
Please also add the logs and a bit more details on what you are trying to do. Please also try to format the above config and logs properly to make them readable.
the log file is full of >>>>>
2018-05-11T08:34:12Z INFO Non-zero metrics in the last 30s: http.unmatched_responses=54 libbeat.es.call_count.PublishEvents=105 libbeat.es.publish.read_bytes=51029 libbeat.es.publish.write_byte
s=3167012 libbeat.es.published_and_acked_events=4537 libbeat.publisher.messages_in_worker_queues=2073 libbeat.publisher.published_events=4520 tcp.dropped_because_of_gaps=231
2018-05-11T08:34:42Z INFO Non-zero metrics in the last 30s: http.unmatched_responses=40 libbeat.es.call_count.PublishEvents=98 libbeat.es.publish.read_bytes=46918 libbeat.es.publish.write_bytes
=2839994 libbeat.es.published_and_acked_events=4097 libbeat.publisher.messages_in_worker_queues=1719 libbeat.publisher.published_events=4119 tcp.dropped_because_of_gaps=185
2018-05-11T08:35:12Z INFO Non-zero metrics in the last 30s: http.unmatched_responses=32 libbeat.es.call_count.PublishEvents=89 libbeat.es.publish.read_bytes=42447 libbeat.es.publish.write_bytes
=2717090 libbeat.es.published_and_acked_events=3784 libbeat.publisher.messages_in_worker_queues=1884 libbeat.publisher.published_events=3782 tcp.dropped_because_of_gaps=77
2018-05-11T08:35:42Z INFO Non-zero metrics in the last 30s: http.unmatched_responses=39 libbeat.es.call_count.PublishEvents=86 libbeat.es.publish.read_bytes=41395 libbeat.es.publish.write_bytes
=2506780 libbeat.es.published_and_acked_events=3576 libbeat.publisher.messages_in_worker_queues=1758 libbeat.publisher.published_events=3540 tcp.dropped_because_of_gaps=105
2018-05-11T08:36:12Z INFO Non-zero metrics in the last 30s: http.unmatched_responses=55 libbeat.es.call_count.PublishEvents=91 libbeat.es.publish.read_bytes=43041 libbeat.es.publish.write_bytes
=2661650 libbeat.es.published_and_acked_events=3666 libbeat.publisher.messages_in_worker_queues=2055 libbeat.publisher.published_events=3691 tcp.dropped_because_of_gaps=126
2018-05-11T08:36:30Z INFO packet decode failed with: Invalid (too small) IP header length (0 < 5)
2018-05-11T08:36:42Z INFO Non-zero metrics in the last 30s: http.unmatched_responses=67 libbeat.es.call_count.PublishEvents=102 libbeat.es.publish.read_bytes=48986 libbeat.es.publish.write_byte
s=3118782 libbeat.es.published_and_acked_events=4319 libbeat.publisher.messages_in_worker_queues=2121 libbeat.publisher.published_events=4295 tcp.dropped_because_of_gaps=180
2018-05-11T08:37:12Z INFO Non-zero metrics in the last 30s: http.unmatched_responses=31 libbeat.es.call_count.PublishEvents=99 libbeat.es.publish.read_bytes=47092 libbeat.es.publish.write_bytes
=2803159 libbeat.es.published_and_acked_events=4035 libbeat.publisher.messages_in_worker_queues=1799 libbeat.publisher.published_events=4054 tcp.dropped_because_of_gaps=130
2018-05-11T08:37:42Z INFO Non-zero metrics in the last 30s: http.unmatched_responses=35 libbeat.es.call_count.PublishEvents=90 libbeat.es.publish.read_bytes=43349 libbeat.es.publish.write_bytes
=2776744 libbeat.es.published_and_acked_events=3842 libbeat.publisher.messages_in_worker_queues=1986 libbeat.publisher.published_events=3852 tcp.dropped_because_of_gaps=131
2018-05-11T08:38:12Z INFO Non-zero metrics in the last 30s: http.unmatched_responses=30 libbeat.es.call_count.PublishEvents=91 libbeat.es.publish.read_bytes=43638 libbeat.es.publish.write_bytes
=2757774 libbeat.es.published_and_acked_events=3844 libbeat.publisher.messages_in_worker_queues=2043 libbeat.publisher.published_events=3830 tcp.dropped_because_of_gaps=59
2018-05-11T08:38:42Z INFO Non-zero metrics in the last 30s: http.unmatched_responses=44 libbeat.es.call_count.PublishEvents=84 libbeat.es.publish.read_bytes=40174 libbeat.es.publish.write_bytes
=2533535 libbeat.es.published_and_acked_events=3507 libbeat.publisher.messages_in_worker_queues=1869 libbeat.publisher.published_events=3528 tcp.dropped_because_of_gaps=119
2018-05-11T08:39:12Z INFO Non-zero metrics in the last 30s: http.unmatched_responses=27 libbeat.es.call_count.PublishEvents=87 libbeat.es.publish.read_bytes=40890 libbeat.es.publish.write_bytes=2509261 libbeat.es.published_and_acked_events=3418 libbeat.publisher.messages_in_worker_queues=2013 libbeat.publisher.published_events=3378 tcp.dropped_because_of_gaps=23
2018-05-11T08:39:42Z INFO Non-zero metrics in the last 30s: http.unmatched_responses=26 libbeat.es.call_count.PublishEvents=76 libbeat.es.publish.read_bytes=35931 libbeat.es.publish.write_bytes=2211417 libbeat.es.published_and_acked_events=3032 libbeat.publisher.messages_in_worker_queues=1720 libbeat.publisher.published_events=3041 tcp.dropped_because_of_gaps=81
2018-05-11T08:40:12Z INFO Non-zero metrics in the last 30s: http.unmatched_responses=26 libbeat.es.call_count.PublishEvents=87 libbeat.es.publish.read_bytes=41027 libbeat.es.publish.write_bytes=2541132 libbeat.es.published_and_acked_events=3444 libbeat.publisher.messages_in_worker_queues=2138 libbeat.publisher.published_events=3436 tcp.dropped_because_of_gaps=37
2018-05-11T08:40:42Z INFO Non-zero metrics in the last 30s: http.unmatched_responses=32 libbeat.es.call_count.PublishEvents=85 libbeat.es.publish.read_bytes=40269 libbeat.es.publish.write_bytes=2533687 libbeat.es.published_and_acked_events=3419 libbeat.publisher.messages_in_worker_queues=2100 libbeat.publisher.published_events=3417 tcp.dropped_because_of_gaps=83
2018-05-11T08:41:12Z INFO Non-zero metrics in the last 30s: http.unmatched_responses=29 libbeat.es.call_count.PublishEvents=87 libbeat.es.publish.read_bytes=41639 libbeat.es.publish.write_bytes=2673085 libbeat.es.published_and_acked_events=3631 libbeat.publisher.messages_in_worker_queues=2229 libbeat.publisher.published_events=3666 tcp.dropped_because_of_gaps=60
2018-05-11T08:41:24Z INFO packet decode failed with: Invalid (too small) IP header length (0 < 5)
Thanks for the details. So if I understand you correctly, you make a http request through curl and get a 200 response but the packet captured by packetbeat says it's a 400? Could you share the full json content of this document to see if there any other interesting bits inside that could give use more details?
Your original request used HTTP/2, which is not supported by Packetbeat, so it was not captured.
The 404 error that you observe in Kibana is for a different path, so it was caused by another request. Is it possible that this request failed with a 404?
Please repeat the scenario by passing the --http1.1 argument to curl, so it doesn't use http2.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.