Ingest IBM MQ logs to Elasticsearch using filebeat module

Hello,

Recently I installed filebeat 7.4.2 and enabled IBM MQ module. After applying new configuration I didn’t get any data to elasticsearch. Inspecting logs, I found following line:

Nov 15 16:07:30 ******** filebeat[16239]: 2019-11-15T16:07:30.797+0100 INFO log/input.go:152 Configured paths: [/var/mqm/*.LOG* /var/mqm/qmgrs/*/*.LOG*]

I released that the default configure log paths is incorrect. With var.paths I have setup right location for logs:

/var/mqm/qmgrs/*/errors/*.LOG*

After applying configuration, I get following logs:

Nov 15 21:30:33 ******** filebeat[23423]: 2019-11-15T21:30:33.718+0100        INFO        log/harvester.go:251        Harvester started for file: /var/mqm/qmgrs/QMRAZ1/errors/AMQERR03.LOG
Nov 15 21:30:33 ******** filebeat[23423]: 2019-11-15T21:30:33.718+0100        INFO        log/harvester.go:251        Harvester started for file: /var/mqm/qmgrs/QMRAZ2/errors/AMQERR01.LOG
Nov 15 21:30:33 ******** filebeat[23423]: 2019-11-15T21:30:33.737+0100        INFO        log/harvester.go:251        Harvester started for file: /var/mqm/qmgrs/QMRAZ2/errors/AMQERR02.LOG
Nov 15 21:30:33 ******** filebeat[23423]: 2019-11-15T21:30:33.762+0100        INFO        log/harvester.go:251        Harvester started for file: /var/mqm/qmgrs/QMRAZ2/errors/AMQERR03.LOG
Nov 15 21:30:33 ******** filebeat[23423]: 2019-11-15T21:30:33.764+0100        INFO        log/harvester.go:251        Harvester started for file: /var/mqm/qmgrs/QMRAZ1/errors/AMQERR02.LOG
Nov 15 21:30:33 ******** filebeat[23423]: 2019-11-15T21:30:33.783+0100        INFO        log/harvester.go:251        Harvester started for file: /var/mqm/qmgrs/QMRAZ1/errors/AMQERR01.LOG

But still I was not able to see any logs in elasticsearch. I have checked ingest pipeline and it seems OK to me.

Has anyone run into the same problem?

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.