I am trying to load the data into logstash which is read by the file beat, but logstash is unable to read the data.
Here are my filebeat debug data that are being generated while running it.
2020-06-11T13:01:41.607+0530 DEBUG [input] log/input.go:511 Update existing file for harvesting: C:\Users\tushar\Documents\logs\STAGE-GEN2_16-02-2020-01-55-53 (1).log, offset: 1824
2020-06-11T13:01:41.607+0530 DEBUG [input] log/input.go:563 Harvester for file is still running: C:\Users\tushar\Documents\logs\STAGE-GEN2_16-02-2020-01-55-53 (1).log
2020-06-11T13:01:41.607+0530 DEBUG [input] log/input.go:421 Check file for harvesting: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_14-02-2020-18-00-08.log
2020-06-11T13:01:41.607+0530 DEBUG [input] log/input.go:511 Update existing file for harvesting: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_14-02-2020-18-00-08.log, offset: 553
2020-06-11T13:01:41.607+0530 DEBUG [input] log/input.go:563 Harvester for file is still running: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_14-02-2020-18-00-08.log
2020-06-11T13:01:41.607+0530 DEBUG [input] log/input.go:421 Check file for harvesting: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_14-12-2019-10-00-07.log
2020-06-11T13:01:41.607+0530 DEBUG [input] log/input.go:511 Update existing file for harvesting: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_14-12-2019-10-00-07.log, offset: 1297
2020-06-11T13:01:41.607+0530 DEBUG [input] log/input.go:563 Harvester for file is still running: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_14-12-2019-10-00-07.log
2020-06-11T13:01:41.608+0530 DEBUG [input] log/input.go:421 Check file for harvesting: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_15-01-2020-22-00-09.log
2020-06-11T13:01:41.608+0530 DEBUG [input] log/input.go:511 Update existing file for harvesting: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_15-01-2020-22-00-09.log, offset: 1414
2020-06-11T13:01:41.608+0530 DEBUG [input] log/input.go:563 Harvester for file is still running: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_15-01-2020-22-00-09.log
2020-06-11T13:01:41.608+0530 DEBUG [input] log/input.go:421 Check file for harvesting: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_15-02-2020-10-00-17.log
2020-06-11T13:01:41.608+0530 DEBUG [input] log/input.go:511 Update existing file for harvesting: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_15-02-2020-10-00-17.log, offset: 553
2020-06-11T13:01:41.608+0530 DEBUG [input] log/input.go:563 Harvester for file is still running: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_15-02-2020-10-00-17.log
2020-06-11T13:01:41.608+0530 DEBUG [input] log/input.go:212 input states cleaned up. Before: 273, After: 273, Pending: 0
Some more like this:
-GEN2_15-02-2020-18-00-14.log; Backoff now.
2020-06-11T13:02:52.453+0530 DEBUG [harvester] log/log.go:107 End of file reached: C:\Users\tushar\Documents\logs\STAGE-GEN2_31-01-2020-13-30-04.log; Backoff now.
2020-06-11T13:02:52.453+0530 DEBUG [harvester] log/log.go:107 End of file reached: C:\Users\tushar\Documents\logs\STAGE-GEN2_16-02-2020-01-55-53.log; Backoff now.
2020-06-11T13:02:52.454+0530 DEBUG [harvester] log/log.go:107 End of file reached: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_23-05-2020-14-00-07 - Copy.log; Backoff now.
2020-06-11T13:02:52.454+0530 DEBUG [harvester] log/log.go:107 End of file reached: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_15-02-2020-14-00-10.log; Backoff now.
2020-06-11T13:02:52.455+0530 DEBUG [harvester] log/log.go:107 End of file reached: C:\Users\tushar\Documents\logs\PIE-GEN2_01-04-2020-21-30-09.log; Backoff now.
2020-06-11T13:02:52.455+0530 DEBUG [harvester] log/log.go:107 End of file reached: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_14-03-2020-16-00-08.log; Backoff now.
2020-06-11T13:02:52.455+0530 DEBUG [harvester] log/log.go:107 End of file reached: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_15-01-2020-20-00-09.log; Backoff now.
2020-06-11T13:02:52.456+0530 DEBUG [harvester] log/log.go:107 End of file reached: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_18-02-2020-14-00-04.log; Backoff now.
2020-06-11T13:02:52.456+0530 DEBUG [harvester] log/log.go:107 End of file reached: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_15-01-2020-13-00-04.log; Backoff now.
2020-06-11T13:02:52.456+0530 DEBUG [harvester] log/log.go:107 End of file reached: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_18-02-2020-14-00-04 (1).log; Backoff now.
2020-06-11T13:02:52.457+0530 DEBUG [harvester] log/log.go:107 End of file reached: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_14-02-2020-13-00-04.log; Backoff now.
2020-06-11T13:02:52.457+0530 DEBUG [harvester] log/log.go:107 End of file reached: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_15-01-2020-10-00-07.log; Backoff now.
2020-06-11T13:02:52.458+0530 DEBUG [harvester] log/log.go:107 End of file reached: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_14-02-2020-19-00-11.log; Backoff now.
2020-06-11T13:02:52.458+0530 DEBUG [harvester] log/log.go:107 End of file reached: C:\Users\tushar\Documents\logs\PRODUCTION-GEN2_14-03-2020-07-00-05.log; Backoff now.
Here is my logstash.conf file:
<input{
beats{
port => "5044"
}
}
filter{
grok{
match => {"message" => "\[%{LOGLEVEL:class}\] %{TIMESTAMP_ISO8601:timestamp} %{GREEDYDATA:javaclass} - %{GREEDYDATA:stackname}-%{GREEDYDATA:versionnumber} %{GREEDYDATA:servicename} \[%{DATA:procedure}\] \[%{DATA:value}\] %{GREEDYDATA:status} \[%{GREEDYDATA:statuscode}\]"}
}
date {
match => ["timestamp", "ISO8601"]
}
}
output{
elasticsearch{
hosts => "http://localhost:9200"
index => "filebeatlogs"
}
stdout{}
}/>
Here is my filebeat.yml output data:
#----------------------------- Logstash output --------------------------------
output.logstash:
The Logstash hosts
hosts: ["http://192.168.0.103:5044"]
Optional SSL. By default is off.
List of root certificates for HTTPS server verifications
#ssl.certificate_authorities: ["/etc/pki/root/ca.pem"]
Certificate for SSL client authentication
#ssl.certificate: "/etc/pki/client/cert.pem"
Client Certificate Key
#ssl.key: "/etc/pki/client/cert.key"
I am not able to see the logs data being read by logstash. Can you tell me why this is happening I think that everything is configured fine to load the data. Thanks in advance.
What changes do I have to make in logstash.yml? I have made host as http.host: "192.168.0.103" so that logstash can be accessed from any other machine. But data is not being pushed to logstash.