Logstash drop newyears eve


(luuk) #1

hey all,

on the night of 31-12 to 1-1 i had an insane log drop on my ELK-stack cluster.

the cluster exists of 2 elasticsearch clusters 8GB memory each and 1 logstash server 4gb memory.
they are recieving syslog messages from about 350 servers.

does anyone have an idea what might be the cause of this?


(Mark Walkom) #2

Is it ongoing?


(luuk) #3

after a restart of the logstash server things were working for a while,
but after a couple of days it started dropping logs again.


(Pascal) #4

Might be this bug. hits everyone on new year...

https://github.com/logstash-plugins/logstash-filter-date/issues/33 or similar issue ?


(system) #5