I am creating this Topic because I really don't know what to do with a behaviour I just noticed.
Actually, I have an Elastic stack which is working and one application server is sending me logs with rsyslog.
Everything works fine but I noticed a loss of logs between 4am and 6am.
I checked on application server and I can see logs in this time slot.
Our Elastic stack is monitored by our Centreon and I did not notice any error on Logstash or Elastic.
Did you ever meet this behaviour ?
Could you help me find the cause of this behaviour ?
I am just sharing some news about this behavior.
In my Logstash configuration I am using Elapsed filter plugin several times because I want to calculate several elapsed time.
One of those elapsed time could last more than a day. For this elapsed time I set timeout with 172800.
Just before I loose some logs I noticed an increasing time for all elapsed time calculate in Logstash.
I have just deactivated the longest elapsed time and my behavior did not reproduce last night.
Does anyone can help me on this please ?
Here is a screen of what is happening right now, top/left graph is showing an increasing in response time, others are showing less and less messages generated.
If I check directly on the server which is generating logs, I am still seeing the same amount of logs generated.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.