Hi, thanks for prompt reply.
I am trying to produce the filebeat log file but unable to creat it:
# ================================== Logging ===================================
# Sets log level. The default log level is info.
# Available log levels are: error, warning, info, debug
logging.level: debug
logging.to_files: true
logging.files:
path: /root/logs/
name: filebeat
keepfiles: 7
permissions: 0644
# At debug level, you can selectively enable logging only for some components.
# To enable all selectors use ["*"]. Examples of other selectors are "beat",
# "publisher", "service".
#logging.selectors: ["*"]
Anyhow, i am sending the output from console:
2021-06-13T11:08:17.809-0300 INFO instance/beat.go:309 Setup Beat: filebeat; Version: 7.13.1
2021-06-13T11:08:17.810-0300 INFO [publisher] pipeline/module.go:113 Beat name: mvdElastick1.verifone.com
2021-06-13T11:08:17.810-0300 WARN beater/filebeat.go:178 Filebeat is unable to load the Ingest Node pipelines for the configured modules because the Elasticsearch output is not configured/enabled. If you have already loaded the Ingest Node pipelines or are using Logstash pipelines, you can ignore this warning.
2021-06-13T11:08:17.810-0300 INFO [monitoring] log/log.go:117 Starting metrics logging every 30s
2021-06-13T11:08:17.810-0300 INFO instance/beat.go:473 filebeat start running.
2021-06-13T11:08:17.813-0300 INFO memlog/store.go:119 Loading data file of '/var/lib/filebeat/registry/filebeat' succeeded. Active transaction id=0
2021-06-13T11:08:17.813-0300 INFO memlog/store.go:124 Finished loading transaction log file for '/var/lib/filebeat/registry/filebeat'. Active transaction id=0
2021-06-13T11:08:17.813-0300 WARN beater/filebeat.go:381 Filebeat is unable to load the Ingest Node pipelines for the configured modules because the Elasticsearch output is not configured/enabled. If you have already loaded the Ingest Node pipelines or are using Logstash pipelines, you can ignore this warning.
2021-06-13T11:08:17.813-0300 INFO [registrar] registrar/registrar.go:109 States Loaded from registrar: 0
2021-06-13T11:08:17.813-0300 INFO [crawler] beater/crawler.go:71 Loading Inputs: 2
2021-06-13T11:08:17.813-0300 INFO log/input.go:157 Configured paths: [/home/dashboards/ingest_data/*.json]
2021-06-13T11:08:17.813-0300 INFO [crawler] beater/crawler.go:141 Starting input (ID: 10382931307721444929)
2021-06-13T11:08:17.814-0300 INFO [crawler] beater/crawler.go:108 Loading and starting Inputs completed. Enabled inputs: 1
2021-06-13T11:08:17.814-0300 INFO cfgfile/reload.go:164 Config reloader started
2021-06-13T11:08:17.814-0300 INFO cfgfile/reload.go:224 Loading of config files completed.
2021-06-13T11:08:17.814-0300 INFO log/harvester.go:302 Harvester started for file: /home/dashboards/ingest_data/cities3.json
2021-06-13T11:08:18.814-0300 INFO [publisher_pipeline_output] pipeline/output.go:143 Connecting to backoff(async(tcp://localhost:5044))
2021-06-13T11:08:18.814-0300 INFO [publisher] pipeline/retry.go:219 retryer: send unwait signal to consumer
2021-06-13T11:08:18.814-0300 INFO [publisher] pipeline/retry.go:223 done
2021-06-13T11:08:18.815-0300 INFO [publisher_pipeline_output] pipeline/output.go:151 Connection to backoff(async(tcp://localhost:5044)) established
2021-06-13T11:08:47.813-0300 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cgroup":{"cpu":{"cfs":{"period":{"us":100000}},"id":"user.slice"},"cpuacct":{"id":"user.slice","total":{"ns":1626467099961}},"memory":{"id":"session-122.scope","mem":{"limit":{"bytes":9223372036854771712},"usage":{"bytes":251543552}}}},"cpu":{"system":{"ticks":30,"time":{"ms":32}},"total":{"ticks":140,"time":{"ms":147},"value":140},"user":{"ticks":110,"time":{"ms":115}}},"handles":{"limit":{"hard":262144,"soft":1024},"open":14},"info":{"ephemeral_id":"861f8e4f-9d78-47d6-9b1f-b5ac7bb46e24","uptime":{"ms":30040}},"memstats":{"gc_next":17458608,"memory_alloc":13547576,"memory_sys":76104704,"memory_total":45222704,"rss":125607936},"runtime":{"goroutines":30}},"filebeat":{"events":{"added":8,"done":8},"harvester":{"open_files":1,"running":1,"started":1}},"libbeat":{"config":{"module":{"running":0},"reloads":1,"scans":1},"output":{"events":{"acked":7,"active":0,"batches":1,"total":7},"read":{"bytes":6},"type":"logstash","write":{"bytes":673}},"pipeline":{"clients":1,"events":{"active":0,"filtered":1,"published":7,"retry":7,"total":8},"queue":{"acked":7,"max_events":4096}}},"registrar":{"states":{"current":1,"update":8},"writes":{"success":2,"total":2}},"system":{"cpu":{"cores":8},"load":{"1":0.49,"15":0.18,"5":0.29,"norm":{"1":0.0613,"15":0.0225,"5":0.0363}}}}}}
At logstash log i can see 7 records instead of the original 8:
{"log":{"offset":44,"file":{"path":"/home/dashboards/ingest_data/cities3.json"}},"ecs":{"version":"1.8.0"},"city":"Sydney","province":"New South Wales","input":{"type":"log"},"@timestamp":"2021-06-13T14:08:17.814Z","host":{"name":"mvdElastick1.company.com"},"@version":"1","agent":{"type":"filebeat","version":"7.13.1","ephemeral_id":"861f8e4f-9d78-47d6-9b1f-b5ac7bb46e24","name":"mvdElastick1.company.com","hostname":"mvdElastick1.company.com","id":"54d7d3c2-2b0e-4e0f-a27d-d6c79d4db85c"}}
{"agent":{"type":"filebeat","version":"7.13.1","ephemeral_id":"861f8e4f-9d78-47d6-9b1f-b5ac7bb46e24","name":"mvdElastick1.company.com","hostname":"mvdElastick1.company.com","id":"54d7d3c2-2b0e-4e0f-a27d-d6c79d4db85c"},"ecs":{"version":"1.8.0"},"city":"South Brunswick","province":"New Jersey","input":{"type":"log"},"@timestamp":"2021-06-13T14:08:17.814Z","host":{"name":"mvdElastick1.company.com"},"log":{"offset":211,"file":{"path":"/home/dashboards/ingest_data/cities3.json"}},"@version":"1"}
{"agent":{"type":"filebeat","version":"7.13.1","ephemeral_id":"861f8e4f-9d78-47d6-9b1f-b5ac7bb46e24","name":"mvdElastick1.company.com","hostname":"mvdElastick1.company.com","id":"54d7d3c2-2b0e-4e0f-a27d-d6c79d4db85c"},"ecs":{"version":"1.8.0"},"city":"Southlake","province":"Texas","input":{"type":"log"},"@timestamp":"2021-06-13T14:08:17.814Z","host":{"name":"mvdElastick1.company.com"},"@version":"1","log":{"offset":114,"file":{"path":"/home/dashboards/ingest_data/cities3.json"}}}
{"agent":{"type":"filebeat","version":"7.13.1","ephemeral_id":"861f8e4f-9d78-47d6-9b1f-b5ac7bb46e24","name":"mvdElastick1.company.com","hostname":"mvdElastick1.company.com","id":"54d7d3c2-2b0e-4e0f-a27d-d6c79d4db85c"},"ecs":{"version":"1.8.0"},"city":"Singapore","input":{"type":"log"},"@timestamp":"2021-06-13T14:08:17.814Z","host":{"name":"mvdElastick1.company.com"},"@version":"1","log":{"offset":92,"file":{"path":"/home/dashboards/ingest_data/cities3.json"}}}
{"log":{"offset":155,"file":{"path":"/home/dashboards/ingest_data/cities3.json"}},"ecs":{"version":"1.8.0"},"city":"South San Francisco","province":"California","input":{"type":"log"},"@timestamp":"2021-06-13T14:08:17.814Z","host":{"name":"mvdElastick1.company.com"},"@version":"1","agent":{"type":"filebeat","version":"7.13.1","ephemeral_id":"861f8e4f-9d78-47d6-9b1f-b5ac7bb46e24","name":"mvdElastick1.company.com","hostname":"mvdElastick1.company.com","id":"54d7d3c2-2b0e-4e0f-a27d-d6c79d4db85c"}}
{"log":{"offset":0,"file":{"path":"/home/dashboards/ingest_data/cities3.json"}},"ecs":{"version":"1.8.0"},"city":"Seattle","province":"Washington","input":{"type":"log"},"@timestamp":"2021-06-13T14:08:17.814Z","host":{"name":"mvdElastick1.company.com"},"@version":"1","agent":{"type":"filebeat","version":"7.13.1","ephemeral_id":"861f8e4f-9d78-47d6-9b1f-b5ac7bb46e24","name":"mvdElastick1.company.com","hostname":"mvdElastick1.company.com","id":"54d7d3c2-2b0e-4e0f-a27d-d6c79d4db85c"}}
{"agent":{"type":"filebeat","version":"7.13.1","ephemeral_id":"861f8e4f-9d78-47d6-9b1f-b5ac7bb46e24","name":"mvdElastick1.company.com","hostname":"mvdElastick1.company.com","id":"54d7d3c2-2b0e-4e0f-a27d-d6c79d4db85c"},"ecs":{"version":"1.8.0"},"city":"Stretford","province":"Manchester","input":{"type":"log"},"@timestamp":"2021-06-13T14:08:17.814Z","host":{"name":"mvdElastick1.company.com"},"log":{"offset":263,"file":{"path":"/home/dashboards/ingest_data/cities3.json"}},"@version":"1"}
Still, i can see only one document at Kibana:
Appreciate any help.
Regards