Hello Everyone,
I'm working in a new logstash plateform built from kafka output, archtiecture is as shown below:
" filebeat -> kafka -> logstash ( first site SSL encryption) -> logstash ( second site ssl decryption) -> elasticsearch -> kibana"
Issue, is shown between ( logstash and the second logstash) instance.
you can find below two différent messages for same "input" from kafka:
logstash (1)
"message": " [Other: 0.5 ms]",
logstash (2)
"caa-bloc": "%{[fields][caa-bloc]}",
"message": "2018-07-02T10:07:56.620Z {name=vl-a-rxx-56} [Other: 0.5 ms]"
and complete JSON message:
logstash (1)
{
"_index": "logs.caa.devrct.applications_59_2018.07.02",
"_type": "doc",
"_id": "FMSAWmQBF5mYg5ij5l8q",
"_version": 1,
"_score": 17.41422,
"_source": {
"caa-bloc": "%{[fields][caa-bloc]}",
"caa-type": "application",
"input": {
"type": "log"
},
"host": {
"name": "vl-a-rxx-56"
},
"offset": 8543392,
"message": " [Other: 0.5 ms]",
"tags": [
"_grokparsefailure"
],
"prospector": {
"type": "log"
},
"caa-allocid": "%{[fields][caa-allocid]}",
"caa-srvip": "10.108.99.222",
"caa-env": "horsprod",
"source": "/apps/kafka/confluent-4.0.0/logs/kafkaServer-gc.log.0.current",
"@version": "1",
"beat": {
"name": "vl-a-rxx-56",
"version": "6.3.0",
"hostname": "vl-a-rxx-56"
},
"log_topic": "logs.caa.devrct.applications",
"caa-module": "kafka",
"caa-image": "%{[fields][caa-image]}",
"topic": "logs.caa.devrct.applications",
"fields": {
"caa-type": "application",
"caa-env": "horsprod",
"log_topic": "logs.caa.devrct.applications",
"caa-module": "kafka",
"caa-srvip": "10.108.99.222",
"caa-host": "vl-a-rxx-56"
},
"timestamp": "%{year}-%{month}-%{day} %{time}",
"caa-type2": "%{[fields][caa-type2]}",
"@timestamp": "2018-07-02T10:19:12.060Z",
"caa-host": "vl-a-rxx-56"
},
"fields": {
"@timestamp": [
"2018-07-02T10:19:12.060Z"
]
},
"highlight": {
"beat.hostname": [
"@kibana-highlighted-field@vl@/kibana-highlighted-field@-@kibana-highlighted-field@a@/kibana-highlighted-field@-@kibana-highlighted-field@rxx@/kibana-highlighted-field@-@kibana-highlighted-field@56@/kibana-highlighted-field@"
],
"message": [
"[@kibana-highlighted-field@Other@/kibana-highlighted-field@: @kibana-highlighted-field@0.5@/kibana-highlighted-field@ @kibana-highlighted-field@ms@/kibana-highlighted-field@]"
]
}
}
logstash (2):
{
"_index": "amlooser_60_2018.07.02",
"_type": "doc",
"_id": "QMOAWmQBF5mYg5ijtf2D",
"_version": 1,
"_score": 2.0808823,
"_source": {
"caa-env": "%{[fields][caa-env]}",
"caa-type2": "%{[fields][caa-type2]}",
"@version": "1",
"topic": "%{[fields][log_topic]}",
"caa-srvip": "%{[fields][caa-srvip]}",
"@timestamp": "2018-07-02T10:19:01.740Z",
"timestamp": "%{year}-%{month}-%{day} %{time}",
"caa-type": "%{[fields][caa-type]}",
"caa-allocid": "%{[fields][caa-allocid]}",
"caa-module": "%{[fields][caa-module]}",
"caa-image": "%{[fields][caa-image]}",
"caa-host": "%{[fields][caa-host]}",
"log_topic": "%{[fields][log_topic]}",
"tags": [
"beats_input_codec_plain_applied",
"_jsonparsefailure",
"_grokparsefailure"
],
"caa-bloc": "%{[fields][caa-bloc]}",
"message": "2018-07-02T10:07:56.620Z {name=vl-a-rxx-56} [Other: 0.5 ms]"
},
"fields": {
"@timestamp": [
"2018-07-02T10:19:01.740Z"
]
},
"highlight": {
"message": [
"2018-07-02T10:07:56.620Z {name=@kibana-highlighted-field@vl@/kibana-highlighted-field@-@kibana-highlighted-field@a@/kibana-highlighted-field@-@kibana-highlighted-field@rxx@/kibana-highlighted-field@-@kibana-highlighted-field@56@/kibana-highlighted-field@} [Other: 0.5 ms]"
]
}
}
Thanks for your participation!