Nginx module - No event published for error log entry

Dear all,
as you can notice in here enclosed filebeat log file in debug mode, filebeat does actually monitor nginx error log file but there is neither event published to elasticsearch nor data available in kibana dashboard.
Thx for your support.
However the file /opt/application/nginxws/logs/error.log does have some entries:

019/07/01 15:58:12 [warn] 3757#0: *18 upstream server temporarily disabled while reading response header from upstream, client: 192.168.2.4, server: 192.168.2.246, request: "GET /admin/base/firepad/token?token=eyJhbGciOiJIUzI1NiJ9.eyJkIjp7ImV4cGlyZXMiOjE1NjIwNjk4ODEsInByb3ZpZGVyIjoicGFzc3dvcmQiLCJ2ZXJpZmllZEF0IjowLCJjcmVhdGVkQXQiOjE0NjcxMjI5NjczMDMsInByb3ZpZGVyVWlkIjoic2FtcGxlc0BsaXN0Lm9yYW5nZS5jb20iLCJ1aWQiOiJlNTdkZjhmYy1hODg3LTRjYmYtYTE0Ny01NjQ0ZGU1ZDc5ZmEifSwiZXhwIjoxNTYyMDY5ODgxLCJpYXQiOjE1NjE5ODM0ODEsInAiOiJ1c2VyIn0.QVCKA5NEcKf9y5iJiVtDoobsKgODe-dmol4ExHQHi7s&1561989491185 HTTP/1.1", upstream: "http://192.168.2.22:8000/admin/base/firepad/token?token=eyJhbGciOiJIUzI1NiJ9.eyJkIjp7ImV4cGlyZXMiOjE1NjIwNjk4ODEsInByb3ZpZGVyIjoicGFzc3dvcmQiLCJ2ZXJpZmllZEF0IjowLCJjcmVhdGVkQXQiOjE0NjcxMjI5NjczMDMsInByb3ZpZGVyVWlkIjoic2FtcGxlc0BsaXN0Lm9yYW5nZS5jb20iLCJ1aWQiOiJlNTdkZjhmYy1hODg3LTRjYmYtYTE0Ny01NjQ0ZGU1ZDc5ZmEifSwiZXhwIjoxNTYyMDY5ODgxLCJpYXQiOjE1NjE5ODM0ODEsInAiOiJ1c2VyIn0.QVCKA5NEcKf9y5iJiVtDoobsKgODe-dmol4ExHQHi7s&1561989491185", host: "io.xxx.com", referrer: "https://io.xxx.com/home"
2019/07/01 15:58:13 [warn] 3756#0: *48 upstream server temporarily disabled while reading response header from upstream, client: 192.168.2.4, server: 192.168.2.246, request: "GET /admin/base/test-sdk-jvm/token?token=eyJhbGciOiJIUzI1NiJ9.eyJkIjp7ImV4cGlyZXMiOjE1NjIwNjk4ODEsInByb3ZpZGVyIjoicGFzc3dvcmQiLCJ2ZXJpZmllZEF0IjowLCJjcmVhdGVkQXQiOjE0NjcxMjI5NjczMDMsInByb3ZpZGVyVWlkIjoic2FtcGxlc0BsaXN0Lm9yYW5nZS5jb20iLCJ1aWQiOiJlNTdkZjhmYy1hODg3LTRjYmYtYTE0Ny01NjQ0ZGU1ZDc5ZmEifSwiZXhwIjoxNTYyMDY5ODgxLCJpYXQiOjE1NjE5ODM0ODEsInAiOiJ1c2VyIn0.QVCKA5NEcKf9y5iJiVtDoobsKgODe-dmol4ExHQHi7s&1561989492994 HTTP/1.1", upstream: "http://192.168.2.22:8000/admin/base/test-sdk-jvm/token?token=eyJhbGciOiJIUzI1NiJ9.eyJkIjp7ImV4cGlyZXMiOjE1NjIwNjk4ODEsInByb3ZpZGVyIjoicGFzc3dvcmQiLCJ2ZXJpZmllZEF0IjowLCJjcmVhdGVkQXQiOjE0NjcxMjI5NjczMDMsInByb3ZpZGVyVWlkIjoic2FtcGxlc0BsaXN0Lm9yYW5nZS5jb20iLCJ1aWQiOiJlNTdkZjhmYy1hODg3LTRjYmYtYTE0Ny01NjQ0ZGU1ZDc5ZmEifSwiZXhwIjoxNTYyMDY5ODgxLCJpYXQiOjE1NjE5ODM0ODEsInAiOiJ1c2VyIn0.QVCKA5NEcKf9y5iJiVtDoobsKgODe-dmol4ExHQHi7s&1561989492994", host: "io.xxx.com", referrer: "https://io.xxx.com/home"
2019-07-01T15:59:43.345+0200    INFO    log/input.go:138        Configured paths: [/opt/application/nginxws/logs/access.log*]
2019-07-01T15:59:43.345+0200    DEBUG   [processors]    processors/processor.go:66      Processors:
2019-07-01T15:59:43.346+0200    DEBUG   [input] log/config.go:200       recursive glob enabled
2019-07-01T15:59:43.346+0200    DEBUG   [input] log/input.go:147        exclude_files: [(?-s:.)gz(?-m:$)]. Number of stats: 3
2019-07-01T15:59:43.346+0200    DEBUG   [input] file/states.go:68       New state added for /opt/application/nginxws/logs/error.log
2019-07-01T15:59:43.346+0200    DEBUG   [input] log/input.go:168        input with previous states loaded: 1
2019-07-01T15:59:43.346+0200    INFO    log/input.go:138        Configured paths: [/opt/application/nginxws/logs/error.log*]
2019-07-01T15:59:43.346+0200    DEBUG   [reload]        cfgfile/list.go:101     Starting runner: nginx (access, error)
2019-07-01T15:59:43.346+0200    INFO    elasticsearch/client.go:163     Elasticsearch url: http://elasticsearch.service.webcom:9200
2019-07-01T15:59:43.347+0200    DEBUG   [elasticsearch] elasticsearch/client.go:688     ES Ping(url=http://elasticsearch.service.webcom:9200)
2019-07-01T15:59:43.354+0200    DEBUG   [elasticsearch] elasticsearch/client.go:711     Ping status code: 200
2019-07-01T15:59:43.354+0200    INFO    elasticsearch/client.go:712     Connected to Elasticsearch version 6.5.1
2019-07-01T15:59:43.354+0200    DEBUG   [modules]       fileset/pipelines.go:45 Required processors: []
2019-07-01T15:59:43.354+0200    DEBUG   [elasticsearch] elasticsearch/client.go:730     GET http://elasticsearch.service.webcom:9200/_ingest/pipeline/filebeat-6.5.1-nginx-error-pipeline  <nil>
2019-07-01T15:59:43.355+0200    DEBUG   [registrar]     registrar/registrar.go:393      Registry file updated. 3 states written.
2019-07-01T15:59:43.355+0200    DEBUG   [registrar]     registrar/registrar.go:345      Processing 1 events
2019-07-01T15:59:43.355+0200    DEBUG   [registrar]     registrar/registrar.go:315      Registrar state updates processed. Count: 1
2019-07-01T15:59:43.355+0200    DEBUG   [registrar]     registrar/registrar.go:335      Registrar states cleaned up. Before: 3, After: 3, Pending: 0
2019-07-01T15:59:43.355+0200    DEBUG   [registrar]     registrar/registrar.go:400      Write registry file: /opt/application/filebeat/data/registry
2019-07-01T15:59:43.355+0200    DEBUG   [acker] beater/acker.go:64      stateful ack    {"count": 1}
2019-07-01T15:59:43.355+0200    DEBUG   [modules]       fileset/pipelines.go:71 Pipeline filebeat-6.5.1-nginx-error-pipeline already loaded
2019-07-01T15:59:43.355+0200    DEBUG   [modules]       fileset/pipelines.go:45 Required processors: [{user_agent ingest-user-agent} {geoip ingest-geoip}]
2019-07-01T15:59:43.356+0200    DEBUG   [elasticsearch] elasticsearch/client.go:730     GET http://elasticsearch.service.webcom:9200/_nodes/ingest  <nil>
2019-07-01T15:59:43.358+0200    DEBUG   [elasticsearch] elasticsearch/client.go:730     GET http://elasticsearch.service.webcom:9200/_ingest/pipeline/filebeat-6.5.1-nginx-access-default  <nil>
2019-07-01T15:59:43.359+0200    DEBUG   [modules]       fileset/pipelines.go:71 Pipeline filebeat-6.5.1-nginx-access-default already loaded
2019-07-01T15:59:43.360+0200    INFO    input/input.go:114      Starting input of type: log; ID: 11343185329277867514
2019-07-01T15:59:43.360+0200    INFO    input/input.go:114      Starting input of type: log; ID: 6831318511820440120
2019-07-01T15:59:43.360+0200    INFO    cfgfile/reload.go:205   Loading of config files completed.
2019-07-01T15:59:43.360+0200    DEBUG   [input] log/input.go:174        Start next scan
2019-07-01T15:59:43.360+0200    DEBUG   [input] log/input.go:404        Check file for harvesting: /opt/application/nginxws/logs/error.log
2019-07-01T15:59:43.361+0200    DEBUG   [input] log/input.go:494        Update existing file for harvesting: /opt/application/nginxws/logs/error.log, offset: 2280
2019-07-01T15:59:43.361+0200    DEBUG   [input] log/input.go:548        File didn't change: /opt/application/nginxws/logs/error.log

After module.d/nginx.yml edit&save + service filebeat restart, I get the event :
'''
2019-07-01T16:43:07.251+0200 DEBUG [publish] pipeline/processor.go:308 Publish event: {
"@timestamp": "2019-07-01T14:43:07.251Z",
"@metadata": {
"beat": "filebeat",
"type": "doc",
"version": "6.5.1",
"pipeline": "filebeat-6.5.1-nginx-error-pipeline"
},
"offset": 3421,
"message": "2019/07/01 16:43:04 [warn] 3756#0: *1429 upstream server temporarily disabled while reading response header from upstream, client: 192.168.2.4, server: 192.168.2.246, request: "GET /admin/base/bigbraintower/token?token=eyJhbGciOiJIUzI1NiJ9.eyJkIjp7ImV4cGlyZXMiOjE1NjIwNjk4ODEsInByb3ZpZGVyIjoicGFzc3dvcmQiLCJ2ZXJpZmllZEF0IjowLCJjcmVhdGVkQXQiOjE0NjcxMjI5NjczMDMsInByb3ZpZGVyVWlkIjoic2FtcGxlc0BsaXN0Lm9yYW5nZS5jb20iLCJ1aWQiOiJlNTdkZjhmYy1hODg3LTRjYmYtYTE0Ny01NjQ0ZGU1ZDc5ZmEifSwiZXhwIjoxNTYyMDY5ODgxLCJpYXQiOjE1NjE5ODM0ODEsInAiOiJ1c2VyIn0.QVCKA5NEcKf9y5iJiVtDoobsKgODe-dmol4ExHQHi7s&1561992184232 HTTP/1.1", upstream: "http://192.168.2.22:8000/admin/base/bigbraintower/token?token=eyJhbGciOiJIUzI1NiJ9.eyJkIjp7ImV4cGlyZXMiOjE1NjIwNjk4ODEsInByb3ZpZGVyIjoicGFzc3dvcmQiLCJ2ZXJpZmllZEF0IjowLCJjcmVhdGVkQXQiOjE0NjcxMjI5NjczMDMsInByb3ZpZGVyVWlkIjoic2FtcGxlc0BsaXN0Lm9yYW5nZS5jb20iLCJ1aWQiOiJlNTdkZjhmYy1hODg3LTRjYmYtYTE0Ny01NjQ0ZGU1ZDc5ZmEifSwiZXhwIjoxNTYyMDY5ODgxLCJpYXQiOjE1NjE5ODM0ODEsInAiOiJ1c2VyIn0.QVCKA5NEcKf9y5iJiVtDoobsKgODe-dmol4ExHQHi7s&1561992184232", host: "io.xxx.com", referrer: "https://io.xxx.com/home"",
"fileset": {
"name": "error",
"module": "nginx"
},
"prospector": {
"type": "log"
},
"input": {
"type": "log"
},
"beat": {
"name": "192.168.2.246",
"hostname": "i-001c911b-rp-ws-server-15354444231.novalocal",
"version": "6.5.1"
},
"host": {
"name": "192.168.2.246"
},
"source": "/opt/application/nginxws/logs/error.log"
}

'''

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.