Hi,
Elasticsearch 5.5.0
Logstash 5.5.0
logstash-codec-multiline 3.0.5
logstash-codec-json 3.0.3.
I'm reading file (NFS) containing JSON lines using above codecs and from time to time receiving only part of line as message value:
Line from log:
{"Validation::Ms":1,"Authentication::Ms":4,"Profile::XId::FindProfile::Ms":2,"SearchQuery:: Ms":2,"Authorization::Ms":22,"DataRule::evaluate::Ms":0,"ActionCode":"XCC_PrSearchRQ","SessionId":"ID-ptnhlp602-35350-1512548256092-0-103068496","AthId":"Shared/IDL:Sess\/SessMgr:1\.0.IDL/Common/!SMS\/RESE!SMSLB\/RES.LB!-3190237126642510194!910228!0!1!E2E-1","ThreadId":"8c80d70d","RequestType":"ProfileSearch","ClCd":"XV","DomainId":"XBNM","ClCnCd":"MYS","ObjectType":"PROFILE","User::ID":"1236","User::Group":"XBNM","User::Domain":"AA","User::HasView":true,"User::HasOSView":false,"DatabaseCalls::Ms::sum":81,"DatabaseCalls::Ms::count":64,"DatabaseCalls::Ms::avg":1.27,"DatabaseCalls::Ms::min":1,"DatabaseCalls::Ms::max":7,"Result":"SUCCESS","TotalTime::Ms":157,"Timestamp":"2018-01-12 11:34:09.743"}
Message value:
Ms":2,"Authorization::Ms":22,"DataRule::evaluate::Ms":0,"ActionCode":"XCC_PrSearchRQ","SessionId":"ID-ptnhlp602-35350-1512548256092-0-103068496","AthId":"Shared/IDL:Sess\/SessMgr:1\.0.IDL/Common/!SMS\/RESE!SMSLB\/RES.LB!-3190237126642510194!910228!0!1!E2E-1","ThreadId":"8c80d70d","RequestType":"ProfileSearch","ClCd":"XV","DomainId":"XBNM","ClCnCd":"MYS","ObjectType":"PROFILE","User::ID":"1236","User::Group":"XBNM","User::Domain":"AA","User::HasView":true,"User::HasOSView":false,"DatabaseCalls::Ms::sum":81,"DatabaseCalls::Ms::count":64,"DatabaseCalls::Ms::avg":1.27,"DatabaseCalls::Ms::min":1,"DatabaseCalls::Ms::max":7,"Result":"SUCCESS","TotalTime::Ms":157,"Timestamp":"2018-01-12 11:34:09.743"}
Logstash configuration:
########################### INPUT ###########################
input {
file {
codec => multiline {
pattern => '^'
negate => true
what => previous
}
path => [
"file1.log",
"file2.log",
"file3.log",
"file4.log",
"file5.log",
"file6.log",
"file7.log",
"file8.log"
]
sincedb_path => "/apps/elk5/logstash/sincedb-tn-ppp_metrics"
type => "mymetrics"
}
}
########################### FILTER ###########################
filter {
if [type] == "mymetrics"
{
json {
source => message
}
########################### OUTPUT ###########################
output {
if [type] == "mymetrics"
{
elasticsearch {
hosts => '127.0.0.1:9200'
index => "mymetrics-%{+YYYY.MM.dd}"
}
}
}
What can cause above ? May it be NFS ?
Thanks in advance !