# logstashでltsvをパースしESへ保存について

**URL:** <https://discuss.elastic.co/t/logstash-ltsv-es/58082>\
**Category:** 日本語による質問・議論はこちら\
**Created:** [August 16, 2016, 2:41am UTC](https://discuss.elastic.co/t/logstash-ltsv-es/58082 "2016-08-16T02:41:13Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![111127](https://avatars.discourse-cdn.com/v4/letter/1/ea666f/32.png) [@111127](https://discuss.elastic.co/u/111127)\
**Post date:** [August 16, 2016, 2:41am UTC](https://discuss.elastic.co/t/logstash-ltsv-es/58082/1 "2016-08-16T02:41:13Z")

</div>

識者の皆様  
初めて投稿をさせていただきます  
よろしくお願い申し上げます

今回、私は以下の様な環境の構築を目指しております  
解析対象：nginxのアクセスログ(ltsv形式)

上記の解析対象のnginxにはfilebeat-1.2.3-1をinstallしてlogstashにアクセスログを送信しています  
logstashはlogstash-2.3.2-1を利用しており、logstashのconfigは以下の通りのようなconfigを設定しています  
【logstash-config】  
input {  
beats {  
port =\> 5044  
}  
}  
#input { stdin {} }

filter {  
kv {  
field\_split =\> "\t"  
value\_split =\> ":"  
}  
date {  
match =\> [time, "'['dd/MMM/YYYY:HH:mm:ss Z']'"]  
locale =\> us  
}  
useragent {  
source =\> ua  
prefix =\> "ua."  
}  
mutate {  
convert =\> {  
status =\> integer  
reqtime =\> integer  
size =\> integer  
}  
}  
}

#output {

# stdout {

# codec =\> rubydebug

# }

#}  
output {  
elasticsearch {  
hosts =\> "ip-address:9200"  
}  
}

上記の設定をして、アクセスログの送信元であるnginxからfilebeatsを利用してlogstash向けにアクセスログを送信をしたのですが、elasticache側にnginxのアクセスログが保存されない状況です  
logstashの/var/log/logstash/logstash.logにはfilebeatsから送信をされてきたltsvのアクセスログが記録されている状況でlogstash.confのfilterが上手く適用をされていない状況です

一度、デバックの為に、outputをrubydebugに設定をして、nginxからfilebeats経由でアクセスログを送信した所、/var/log/logstash/logstash.stdoutには、nginxからfilebeats経由で送信されてきたアクセスログがjson形式でパースされて保存をされていました

色々と試行錯誤をしながら、検証を進めているのですが、今のところ解決策が見えない状況です  
この問題を解決するためには、どのように対応すればよいかご指導をいただけますと幸いです

また、elasticsearch(3ノード)+kibanaに関しては、下記、サイトを参考に構築をしております  
どうぞよろしくお願い申し上げます  
【参考サイト】

> **[Amazon EC2 を使用して Elasticsearch クラスタをセットアップする
	  	 | Elastic](https://www.elastic.co/jp/blog/setting-up-es-cluster-on-ec2)**
>
> Amazon Web Service や、Microsoft Azure の IaaS 環境に、 Elastic Stack をインストールして運用されるケースが増えています。ここでは、Amazon EC2 インスタンスに Elasticsearch 2.3.2、Kibana 4.5.0 をインストールする方法を紹介します。 クラスタの構成VPCにひとつ、もしくは複数の EC2 インスタンスをセッ...

---

<div class="post-metadata">

**Author:** ![johtani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johtani/32/44956_2.png) [@johtani](https://discuss.elastic.co/u/johtani)\
**Post date:** [August 22, 2016, 12:31am UTC](https://discuss.elastic.co/t/logstash-ltsv-es/58082/2 "2016-08-22T00:31:14Z")

</div>

logstashのログやElasticsearchのログにエラーなどは出ていないでしょうか？

---

<div class="post-metadata">

**Author:** ![111127](https://avatars.discourse-cdn.com/v4/letter/1/ea666f/32.png) [@111127](https://discuss.elastic.co/u/111127)\
**Post date:** [August 22, 2016, 12:54am UTC](https://discuss.elastic.co/t/logstash-ltsv-es/58082/3 "2016-08-22T00:54:25Z")

</div>

Ohtani-san

ご指導を頂きまして、有難うございます  
あれから、試行錯誤を繰り返し、logstashの設定を下記のように設定をした所、kibanaにデータを登録することが出来ました

【logstash.conf】

input {  
beats {  
port =\> 5044  
}  
}

filter {

# LTSV形式用

kv {  
field\_split =\> "\t"  
value\_split =\> ":"  
}  
mutate {  
# "2015-08-02 09:51:35,117" -\> "2015-08-02 09:51:35"  
gsub =\> [time, ",[\d][\d][\d]", ""]  
# messageフィールドの削除  
remove\_field =\> ["message"]  
}  
date {  
# timeフィールドを日付形式へ変換（@timestamp）  
match =\> [time, "YYYY-MM-dd HH:mm:ss"]  
timezone =\> "Asia/Tokyo"  
}  
}

output {  
elasticsearch {  
hosts =\> "10.10.11.232"  
index =\> "logstash-%{+YYYY.MM.dd}"  
manage\_template =\> false  
}  
}

この設定でkibanaでlogstash、@timestampでindexを作成をして、Discoverのタブでデータを確認していると  
下記のようなエラーがkibanaのDiscoverのタブに出力をされます  
【kibana-Discover-error】  
Error: unknown error  
ErrorAbstract@[http://10.10.11.64:5601/bundles/kibana.bundle.js?v=10000:64853:29](http://10.10.11.64:5601/bundles/kibana.bundle.js?v=10000:64853:29)  
Generic@[http://10.10.11.64:5601/bundles/kibana.bundle.js?v=10000:64899:22](http://10.10.11.64:5601/bundles/kibana.bundle.js?v=10000:64899:22)  
respond@[http://10.10.11.64:5601/bundles/kibana.bundle.js?v=10000:66222:34](http://10.10.11.64:5601/bundles/kibana.bundle.js?v=10000:66222:34)  
checkRespForFailure@[http://10.10.11.64:5601/bundles/kibana.bundle.js?v=10000:66183:15](http://10.10.11.64:5601/bundles/kibana.bundle.js?v=10000:66183:15)  
[http://10.10.11.64:5601/bundles/kibana.bundle.js?v=10000:64801:10](http://10.10.11.64:5601/bundles/kibana.bundle.js?v=10000:64801:10)  
processQueue@[http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:41883:31](http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:41883:31)  
[http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:41899:40](http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:41899:40)  
$eval@[http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:43127:29](http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:43127:29)  
$digest@[http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:42938:37](http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:42938:37)  
$apply@[http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:43235:32](http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:43235:32)  
done@[http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:37684:54](http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:37684:54)  
completeRequest@[http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:37882:16](http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:37882:16)  
requestError@[http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:37833:25](http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:37833:25)

また、kibanaのkibana.stdoutには下記の様なerrorが記録されています  
【/var/log/kibana.stdoutのlog】  
{"type":"log","@timestamp":"2016-08-19T01:54:47+00:00","tags":["warning","elasticsearch"],"pid":22181,"message":"Unable to revive connection: [http://10.10.11.36:9200/](http://10.10.11.36:9200/)"}  
{"type":"log","@timestamp":"2016-08-19T01:54:47+00:00","tags":["warning","elasticsearch"],"pid":22181,"message":"No living connections"}  
{"type":"response","@timestamp":"2016-08-19T01:54:47+00:00","tags":[],"pid":22181,"method":"post","statusCode":502,"req":{"url":"/elasticsearch/logstash-/\_field\_stats?level=indices","method":"post","headers":{"host":"10.10.11.64:5601","user-agent":"Mozilla/5.0  
(Macintosh; Intel Mac OS X 10.10; rv:47.0) Gecko/20100101  
Firefox/47.0","accept":"application/json, text/plain, \*/","accept-language":"ja,en-US;q=0.7,en;q=0.3","accept-encoding":"gzip,

deflate","content-type":"application/json;charset=utf-8","kbn-version":"4.5.4","referer":"[http://10.10.11.64:5601/app/kibana","content-length":"178","connection":"keep-alive"},"remoteAddress":"192.168.200.41","userAgent":"192.168.200.41","referer":"http://10.10.11.64:5601/app/kibana"},"res":{"statusCode":502,"responseTime":3,"contentLength":9},"message":"POST](http://10.10.11.64:5601/app/kibana%22,%22content-length%22:%22178%22,%22connection%22:%22keep-alive%22%7D,%22remoteAddress%22:%22192.168.200.41%22,%22userAgent%22:%22192.168.200.41%22,%22referer%22:%22http://10.10.11.64:5601/app/kibana%22%7D,%22res%22:%7B%22statusCode%22:502,%22responseTime%22:3,%22contentLength%22:9%7D,%22message%22:%22POST)  
/elasticsearch/logstash-\*/\_field\_stats?level=indices 502 3ms - 9.0B"}

これは、どのように対応すれば解決できますでしょうか  
ご指導をよろしくお願い申し上げます

---

<div class="post-metadata">

**Author:** ![johtani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johtani/32/44956_2.png) [@johtani](https://discuss.elastic.co/u/johtani)\
**Post date:** [August 22, 2016, 1:40am UTC](https://discuss.elastic.co/t/logstash-ltsv-es/58082/4 "2016-08-22T01:40:56Z")

</div>

KibanaのあるマシンからElasticsearchへの接続ができているかは確認されていますか？  
また、Elasticsearchのログは確認されていますか？

あと、エラーログや設定はMarkdownの```でくると見やすくできるので、活用してください。

```auto
こんな感じ

```

---

<div class="post-metadata">

**Author:** ![111127](https://avatars.discourse-cdn.com/v4/letter/1/ea666f/32.png) [@111127](https://discuss.elastic.co/u/111127)\
**Post date:** [August 22, 2016, 1:53am UTC](https://discuss.elastic.co/t/logstash-ltsv-es/58082/5 "2016-08-22T01:53:02Z")

</div>

Ohtani様

ご指導ありがとうございます  
kibanaからelasticsearchに関しては接続ができています  
【確認方法】  
telnet elasticsearch 9200  
※上記のcliでkibanaからelasticsearchの9200にtelnetの接続ができています

また、elasticsearchの/var/log/elasticsearch.logには下記の様なlogが記録されていました  
【elasticsearch.log】

```auto
[2016-08-21 01:00:00,002][INFO][marvel.agent.exporter.local] local exporter [default_local] - cleaning up [1] old indices
[2016-08-21 01:00:00,095][ERROR][marvel.agent.exporter.local] local exporter [default_local] - failed to delete indices
RemoteTransportException[[Bird-Man][10.10.11.90:9300][indices:admin/delete]]; nested: IndexNotFoundException[no such index];
Caused by: [.marvel-es-1-2016.08.14] IndexNotFoundException[no such index]
    at org.elasticsearch.cluster.metadata.MetaDataDeleteIndexService$1.execute(MetaDataDeleteIndexService.java:91)
    at org.elasticsearch.cluster.ClusterStateUpdateTask.execute(ClusterStateUpdateTask.java:45)
    at org.elasticsearch.cluster.service.InternalClusterService.runTasksForExecutor(InternalClusterService.java:468)
    at org.elasticsearch.cluster.service.InternalClusterService$UpdateTask.run(InternalClusterService.java:772)
    at org.elasticsearch.common.util.concurrent.PrioritizedEsThreadPoolExecutor$TieBreakingPrioritizedRunnable.runAndClean(PrioritizedEsThreadPoolExecutor.java:231)
    at org.elasticsearch.common.util.concurrent.PrioritizedEsThreadPoolExecutor$TieBreakingPrioritizedRunnable.run(PrioritizedEsThreadPoolExecutor.java:194)
    at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)
    at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)
    at java.lang.Thread.run(Thread.java:745)
[2016-08-21 05:43:38,478][ERROR][license.plugin.core] [Robert da Costa] 
#
# License will expire on [Friday, September 09, 2016]. If you have a new license, please update it.
# Otherwise, please reach out to your support contact.
# 
# Commercial plugins operate with reduced functionality on license expiration:
# - marvel
# - The agent will stop collecting cluster and indices metrics
# - The agent will stop automatically cleaning indices older than [marvel.history.duration]

```

このような状況なのですが、どのような対策が考えられるでしょうか

---

<div class="post-metadata">

**Author:** ![johtani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johtani/32/44956_2.png) [@johtani](https://discuss.elastic.co/u/johtani)\
**Post date:** [August 22, 2016, 2:06am UTC](https://discuss.elastic.co/t/logstash-ltsv-es/58082/6 "2016-08-22T02:06:30Z")

</div>

このログはKibanaとはおそらく関係ないかと。  
Kibanaでエラーが出た時間帯でログは出てないでしょうか？

Kibanaのログだと、Esのサーバ(10.10.11.36)へのコネクションがおかしいと出ています。  
Discoverを見ていると時々エラーが出るということでしょうか？  
それとも、最初からエラーが出るんでしょうか？

---

<div class="post-metadata">

**Author:** ![111127](https://avatars.discourse-cdn.com/v4/letter/1/ea666f/32.png) [@111127](https://discuss.elastic.co/u/111127)\
**Post date:** [August 22, 2016, 2:28am UTC](https://discuss.elastic.co/t/logstash-ltsv-es/58082/7 "2016-08-22T02:28:13Z")

</div>

Ohtani様

ご指導ありがとうございます  
現状として、以下の2点で問題があると認識しています  
１．kinabaのDiscoverのタブを選択をしており、リフレッシュ時間を30秒とかに設定しておくと、時々エラーが発生をして、そのエラーのmore infoのクリックすると、下記の様なerrorが出てきます  
【エラー】

```auto
Error: unknown error
ErrorAbstract@http://10.10.11.64:5601/bundles/kibana.bundle.js?v=10000:64853:29
Generic@http://10.10.11.64:5601/bundles/kibana.bundle.js?v=10000:64899:22
respond@http://10.10.11.64:5601/bundles/kibana.bundle.js?v=10000:66222:34
checkRespForFailure@http://10.10.11.64:5601/bundles/kibana.bundle.js?v=10000:66183:15
http://10.10.11.64:5601/bundles/kibana.bundle.js?v=10000:64801:10
processQueue@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:41883:31
http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:41899:40
$eval@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:43127:29
$digest@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:42938:37
$apply@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:43235:32
done@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:37684:54
completeRequest@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:37882:16
requestError@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:37833:25

```

２．Discoverのタブでlogstash-\*のAvailable Fieldsでhostのindexをクリックして、Visualizeをクリックしてhostのの状況を可視化をしようとすると、下記の様エラーになります  
【エラー】

```auto
Error: Request to Elasticsearch failed: {"error":{"root_cause":[{"type":"illegal_state_exception","reason":"Field data loading is forbidden on [host]"}],"type":"search_phase_execution_exception","reason":"all shards failed","phase":"query","grouped":true,"failed_shards":[{"shard":0,"index":"logstash-2016.08.22","node":"z0aT3-4PSX6pALMasGgPUw","reason":{"type":"illegal_state_exception","reason":"Field data loading is forbidden on [host]"}}]}}
KbnError@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:61367:21
RequestFailure@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:61400:6
callResponseHandlers/<@http://10.10.11.64:5601/bundles/kibana.bundle.js?v=10000:90178:39
__WEBPACK_AMD_DEFINE_RESULT__ </</Promise.try@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:63911:20
__WEBPACK_AMD_DEFINE_RESULT__ </</Promise.map/<@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:63880:17
__WEBPACK_AMD_DEFINE_RESULT__ </</Promise.map@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:63879:27
callResponseHandlers@http://10.10.11.64:5601/bundles/kibana.bundle.js?v=10000:90150:15
fetchWithStrategy/<@http://10.10.11.64:5601/bundles/kibana.bundle.js?v=10000:89651:17
processQueue@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:41883:29
scheduleProcessQueue/<@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:41899:28
$RootScopeProvider/this.$get</Scope.prototype.$eval@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:43127:17
$RootScopeProvider/this.$get</Scope.prototype.$digest@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:42938:16
$RootScopeProvider/this.$get</Scope.prototype.$apply@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:43235:14
done@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:37684:37
completeRequest@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:37882:8
requestLoaded@http://10.10.11.64:5601/bundles/commons.bundle.js?v=10000:37823:10

```

これもkibanaに問題ではなくelasticseachに問題でしょうか？  
それとも、filebeats→logstash経由で正しくelasticsearchにdataが登録されていないことが原因なのでしょうか

---

<div class="post-metadata">

**Author:** ![johtani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johtani/32/44956_2.png) [@johtani](https://discuss.elastic.co/u/johtani)\
**Post date:** [August 22, 2016, 2:56am UTC](https://discuss.elastic.co/t/logstash-ltsv-es/58082/8 "2016-08-22T02:56:07Z")

</div>

2に関しては`host`というフィールドがAggregationに向いていないフィールドになっているかと。  
おそら`host.raw`というようなフィールドがあると思うでのそちらを使用してみてください。

---

<div class="post-metadata">

**Author:** ![111127](https://avatars.discourse-cdn.com/v4/letter/1/ea666f/32.png) [@111127](https://discuss.elastic.co/u/111127)\
**Post date:** [August 22, 2016, 3:03am UTC](https://discuss.elastic.co/t/logstash-ltsv-es/58082/9 "2016-08-22T03:03:15Z")

</div>

ohtani様

ご指導ありがとう御座います  
host.raw という項目はsettingsの中のfieldsにあるのですが、Discoverの項目の中にはhost.rawという項目はありません  
これは、別途、index等の設定が必要なのでしょうか？

 ![](https://us1.discourse-cdn.com/elastic/original/2X/2/2898f74b6b4e70b27d4d20ec7c0ccb7fdbf72b3c.png)

 ![](https://us1.discourse-cdn.com/elastic/original/2X/e/e46b02f649ed51519506a29bc439e6de00306eb1.png)

---

<div class="post-metadata">

**Author:** ![johtani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johtani/32/44956_2.png) [@johtani](https://discuss.elastic.co/u/johtani)\
**Post date:** [August 22, 2016, 4:29am UTC](https://discuss.elastic.co/t/logstash-ltsv-es/58082/10 "2016-08-22T04:29:56Z")

</div>

Visualizeの画面では選択できます。

Discoverでは、基本的には表示できる項目が出ているだけです。  
`Available Fields`の横にある設定ボタンを`missing`のフィルタを外せば表示はされます。

---

<div class="post-metadata">

**Author:** ![111127](https://avatars.discourse-cdn.com/v4/letter/1/ea666f/32.png) [@111127](https://discuss.elastic.co/u/111127)\
**Post date:** [August 22, 2016, 5:44am UTC](https://discuss.elastic.co/t/logstash-ltsv-es/58082/11 "2016-08-22T05:44:06Z")

</div>

ohtaniさん

頂いいたご指導で試した所、host.rawの項目を表示できました  
そこで、Visualizeをクリックすると、hostの可視化も出来たのですが、再度、discoverの項目に行くと  
host.rawが消えていました

これは都度、Hide Missing Fieldsのチェックをはずさないと行けないのでしょうか？  
常時、Hide Missing Fieldsの項目させることはできないのでしょうか

---

<div class="post-metadata">

**Author:** ![johtani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johtani/32/44956_2.png) [@johtani](https://discuss.elastic.co/u/johtani)\
**Post date:** [August 23, 2016, 5:18am UTC](https://discuss.elastic.co/t/logstash-ltsv-es/58082/12 "2016-08-23T05:18:05Z")

</div>

現状はないかと。必要そうであれば、KibanaのGitHubのIssueに追加をお願いします。

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:46pm UTC](https://discuss.elastic.co/t/logstash-ltsv-es/58082/13 "2017-07-06T13:46:16Z")

</div>


