Note, there is no functionality to remove first part of the message. Yet, first big part of it is missing. In log file such line looks like the following:
2019-03-05 17:34:54.653 prod Azure L_______________n Info 1 L_______________n logged lead [string:messageType:"leadLogged"] [string:leadChannel:"MarketPlace"] [string:leadSource:"p________________e"] [string:leadType:"Phone"]
Please, disregard underscores. There I've replaced some actual data.
I've checked log files and nowhere I could find a line starting with "s" as it is shown in the screenshot document.
Wondering what is wrong with Logstash and How could I fix it if it is possible at all?
Over last 7 days we have only 2 such cases. So the error is rare, yet persistent.
Those log files are filled with data sometime number of times per second.
While file is literally just updated, it might be updated within milliseconds after that.
Might such high write activity on log files cause some sort of concurrency issue?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.