Hi all, I've upgraded to Logstash 7.14 from 7.11, and now I'm having to deal with the geoip databasemanager. My servers do not have direct database access and need to go out via proxy.
Current observed behaviour is that the failing connection (packets being dropped) seems to cause Logstash to hang the pipeline, which is surprising from the documentation. I managed to find the following log entry:
Hmmm, don't attempt to configure proxy at the Java level.... what a mess, particularly as relates to things like Elasticsearch outputs and ... well lot's of other potential things.
Probably better to use the regular geoipupdate tool and a specified 'database' for now at least.
For anyone else using Ansible to deploy Logstash, I've put part of my playbook as a public Gist. This deploys MaxMind's geoipupdate (direct from MaxMind) and configures it according to variables to use a proxy.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.