[2022-07-22T22:03:19,441][INFO ][logstash.runner ] Log4j configuration path used is: /etc/logstash/log4j2.properties
[2022-07-22T22:03:19,446][INFO ][logstash.runner ] Starting Logstash {"logstash.version"=>"7.17.5", "jruby.version"=>"jruby 9.2.20.1 (2.5.8) 2021-11-30 2a2962fbd1 OpenJDK 64-Bit Server VM 11.0.15+10 on 11.0.15+10 +indy +jit [linux-x86_64]"}
[2022-07-22T22:03:19,447][INFO ][logstash.runner ] JVM bootstrap flags: [-Xms1g, -Xmx1g, -XX:+UseConcMarkSweepGC, -XX:CMSInitiatingOccupancyFraction=75, -XX:+UseCMSInitiatingOccupancyOnly, -Djava.awt.headless=true, -Dfile.encoding=UTF-8, -Djdk.io.File.enableADS=true, -Djruby.compile.invokedynamic=true, -Djruby.jit.threshold=0, -Djruby.regexp.interruptible=true, -XX:+HeapDumpOnOutOfMemoryError, -Djava.security.egd=file:/dev/urandom, -Dlog4j2.isThreadContextMapInheritable=true]
[2022-07-22T22:03:20,150][INFO ][logstash.agent ] Successfully started Logstash API endpoint {:port=>9600, :ssl_enabled=>false}
[2022-07-22T22:03:22,198][INFO ][org.reflections.Reflections] Reflections took 39 ms to scan 1 urls, producing 119 keys and 419 values
[2022-07-22T22:03:28,381][INFO ][logstash.filters.ruby.script] Test run complete {:script_path=>"/usr/share/logstash/scripts/identities.rb", :results=>{:passed=>0, :failed=>0, :errored=>0}}
[2022-07-22T22:03:28,387][INFO ][logstash.filters.ruby.script] Test run complete {:script_path=>"/usr/share/logstash/scripts/custom_timestamp.rb", :results=>{:passed=>0, :failed=>0, :errored=>0}}
[2022-07-22T22:03:28,455][INFO ][logstash.filters.ruby.script] Test run complete {:script_path=>"/usr/share/logstash/scripts/custom_timestamp.rb", :results=>{:passed=>0, :failed=>0, :errored=>0}}
[2022-07-22T22:03:28,517][INFO ][logstash.filters.ruby.script] Test run complete {:script_path=>"/usr/share/logstash/scripts/custom_timestamp.rb", :results=>{:passed=>0, :failed=>0, :errored=>0}}
[2022-07-22T22:03:28,650][INFO ][logstash.outputs.elasticsearch][main] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["//10.81.1.248:9200"]}
[2022-07-22T22:03:28,834][INFO ][logstash.outputs.elasticsearch][main] Elasticsearch pool URLs updated {:changes=>{:removed=>[], :added=>[http://10.81.1.248:9200/]}}
[2022-07-22T22:03:28,934][WARN ][logstash.outputs.elasticsearch][main] Restored connection to ES instance {:url=>"http://10.81.1.248:9200/"}
[2022-07-22T22:03:28,941][INFO ][logstash.outputs.elasticsearch][main] Elasticsearch version determined (7.16.2) {:es_version=>7}
[2022-07-22T22:03:28,942][WARN ][logstash.outputs.elasticsearch][main] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document _type {:es_version=>7}
[2022-07-22T22:03:28,977][INFO ][logstash.outputs.elasticsearch][main] Config is not compliant with data streams. `data_stream => auto` resolved to `false`
[2022-07-22T22:03:28,978][INFO ][logstash.outputs.elasticsearch][main] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["//10.81.1.248:9200"]}
[2022-07-22T22:03:28,983][INFO ][logstash.outputs.elasticsearch][main] Elasticsearch pool URLs updated {:changes=>{:removed=>[], :added=>[http://10.81.1.248:9200/]}}
[2022-07-22T22:03:28,990][WARN ][logstash.outputs.elasticsearch][main] Restored connection to ES instance {:url=>"http://10.81.1.248:9200/"}
[2022-07-22T22:03:28,994][INFO ][logstash.outputs.elasticsearch][main] Elasticsearch version determined (7.16.2) {:es_version=>7}
[2022-07-22T22:03:28,994][WARN ][logstash.outputs.elasticsearch][main] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document _type {:es_version=>7}
[2022-07-22T22:03:28,998][INFO ][logstash.outputs.elasticsearch][main] Using mapping template from {:path=>"/usr/share/logstash/template/iplogs-metrics-template.json"}
[2022-07-22T22:03:29,010][INFO ][logstash.outputs.elasticsearch][main] Installing Elasticsearch template {:name=>"iplogs-metrics"}
[2022-07-22T22:03:29,014][INFO ][logstash.outputs.elasticsearch][main] Config is not compliant with data streams. `data_stream => auto` resolved to `false`
[2022-07-22T22:03:29,014][INFO ][logstash.outputs.elasticsearch][main] Config is not compliant with data streams. `data_stream => auto` resolved to `false`
[2022-07-22T22:03:29,015][INFO ][logstash.outputs.elasticsearch][main] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["//10.81.1.248:9200"]}
[2022-07-22T22:03:29,021][INFO ][logstash.outputs.elasticsearch][main] Using mapping template from {:path=>"/usr/share/logstash/template/proxylogs-template.json"}
[2022-07-22T22:03:29,023][INFO ][logstash.outputs.elasticsearch][main] Elasticsearch pool URLs updated {:changes=>{:removed=>[], :added=>[http://10.81.1.248:9200/]}}
[2022-07-22T22:03:29,032][INFO ][logstash.outputs.elasticsearch][main] Installing Elasticsearch template {:name=>"proxylogs"}
[2022-07-22T22:03:29,032][WARN ][logstash.outputs.elasticsearch][main] Restored connection to ES instance {:url=>"http://10.81.1.248:9200/"}
[2022-07-22T22:03:29,036][INFO ][logstash.outputs.elasticsearch][main] Elasticsearch version determined (7.16.2) {:es_version=>7}
[2022-07-22T22:03:29,036][WARN ][logstash.outputs.elasticsearch][main] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document _type {:es_version=>7}
[2022-07-22T22:03:29,053][INFO ][logstash.outputs.elasticsearch][main] Config is not compliant with data streams. `data_stream => auto` resolved to `false`
[2022-07-22T22:03:29,053][INFO ][logstash.outputs.elasticsearch][main] Config is not compliant with data streams. `data_stream => auto` resolved to `false`
[2022-07-22T22:03:29,053][INFO ][logstash.outputs.elasticsearch][main] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["//10.81.1.248:9200"]}
[2022-07-22T22:03:29,057][INFO ][logstash.outputs.elasticsearch][main] Using mapping template from {:path=>"/usr/share/logstash/template/proxylogs-metrics-template.json"}
[2022-07-22T22:03:29,058][INFO ][logstash.outputs.elasticsearch][main] Elasticsearch pool URLs updated {:changes=>{:removed=>[], :added=>[http://10.81.1.248:9200/]}}
[2022-07-22T22:03:29,061][INFO ][logstash.outputs.elasticsearch][main] Installing Elasticsearch template {:name=>"proxylogs-metrics"}
[2022-07-22T22:03:29,061][WARN ][logstash.outputs.elasticsearch][main] Restored connection to ES instance {:url=>"http://10.81.1.248:9200/"}
[2022-07-22T22:03:29,063][INFO ][logstash.outputs.elasticsearch][main] Elasticsearch version determined (7.16.2) {:es_version=>7}
[2022-07-22T22:03:29,063][WARN ][logstash.outputs.elasticsearch][main] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document _type {:es_version=>7}
[2022-07-22T22:03:29,080][INFO ][logstash.outputs.elasticsearch][main] Config is not compliant with data streams. `data_stream => auto` resolved to `false`
[2022-07-22T22:03:29,080][INFO ][logstash.outputs.elasticsearch][main] Config is not compliant with data streams. `data_stream => auto` resolved to `false`
[2022-07-22T22:03:29,080][INFO ][logstash.outputs.elasticsearch][main] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["https://*************.es.europe-west2.gcp.elastic-cloud.com:9243"]}
[2022-07-22T22:03:29,085][INFO ][logstash.outputs.elasticsearch][main] Using mapping template from {:path=>"/usr/share/logstash/template/iplogs-template.json"}
[2022-07-22T22:03:29,089][INFO ][logstash.outputs.elasticsearch][main] Installing Elasticsearch template {:name=>"iplogs"}
[2022-07-22T22:03:29,090][INFO ][logstash.outputs.elasticsearch][main] Elasticsearch pool URLs updated {:changes=>{:removed=>[], :added=>[https://logstash:xxxxxx@*************.es.europe-west2.gcp.elastic-cloud.com:9243/]}}
[2022-07-22T22:03:29,568][WARN ][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"https://logstash:xxxxxx@*************.es.europe-west2.gcp.elastic-cloud.com:9243/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :message=>"Got response code '401' contacting Elasticsearch at URL 'https://*************.es.europe-west2.gcp.elastic-cloud.com:9243/'"}
[2022-07-22T22:03:29,569][INFO ][logstash.outputs.elasticsearch][main] Config is not compliant with data streams. `data_stream => auto` resolved to `false`
[2022-07-22T22:03:29,570][INFO ][logstash.outputs.elasticsearch][main] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["//10.81.1.248:9200"]}
[2022-07-22T22:03:29,574][INFO ][logstash.outputs.elasticsearch][main] Elasticsearch pool URLs updated {:changes=>{:removed=>[], :added=>[http://10.81.1.248:9200/]}}
[2022-07-22T22:03:29,578][WARN ][logstash.outputs.elasticsearch][main] Restored connection to ES instance {:url=>"http://10.81.1.248:9200/"}
[2022-07-22T22:03:29,580][INFO ][logstash.outputs.elasticsearch][main] Elasticsearch version determined (7.16.2) {:es_version=>7}
[2022-07-22T22:03:29,580][WARN ][logstash.outputs.elasticsearch][main] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document _type {:es_version=>7}
[2022-07-22T22:03:29,599][INFO ][logstash.outputs.elasticsearch][main] Config is not compliant with data streams. `data_stream => auto` resolved to `false`
[2022-07-22T22:03:29,599][INFO ][logstash.outputs.elasticsearch][main] Config is not compliant with data streams. `data_stream => auto` resolved to `false`
[2022-07-22T22:03:29,603][INFO ][logstash.outputs.elasticsearch][main] Using mapping template from {:path=>"/usr/share/logstash/template/dnslogs-metrics-template.json"}
[2022-07-22T22:03:29,606][INFO ][logstash.outputs.elasticsearch][main] Installing Elasticsearch template {:name=>"dnslogs-metrics"}
[2022-07-22T22:03:29,670][INFO ][logstash.filters.geoip.databasemanager][main] GeoIP database path is configured manually so the plugin will not check for update. Keep in mind that if you are not using the database shipped with this plugin, please go to https://www.maxmind.com/en/geolite2/eula and understand the terms and conditions.
[2022-07-22T22:03:29,670][INFO ][logstash.filters.geoip ][main] Using geoip database {:path=>"/usr/share/logstash/maxmind/GeoLite2-ASN.mmdb"}
[2022-07-22T22:03:29,686][INFO ][logstash.filters.geoip.databasemanager][main] GeoIP database path is configured manually so the plugin will not check for update. Keep in mind that if you are not using the database shipped with this plugin, please go to https://www.maxmind.com/en/geolite2/eula and understand the terms and conditions.
[2022-07-22T22:03:29,686][INFO ][logstash.filters.geoip ][main] Using geoip database {:path=>"/usr/share/logstash/maxmind/GeoLite2-ASN.mmdb"}
[2022-07-22T22:03:29,687][INFO ][logstash.filters.geoip.databasemanager][main] GeoIP database path is configured manually so the plugin will not check for update. Keep in mind that if you are not using the database shipped with this plugin, please go to https://www.maxmind.com/en/geolite2/eula and understand the terms and conditions.
[2022-07-22T22:03:29,687][INFO ][logstash.filters.geoip ][main] Using geoip database {:path=>"/usr/share/logstash/maxmind/GeoLite2-ASN.mmdb"}
[2022-07-22T22:03:29,688][INFO ][logstash.filters.geoip.databasemanager][main] GeoIP database path is configured manually so the plugin will not check for update. Keep in mind that if you are not using the database shipped with this plugin, please go to https://www.maxmind.com/en/geolite2/eula and understand the terms and conditions.
[2022-07-22T22:03:29,688][INFO ][logstash.filters.geoip ][main] Using geoip database {:path=>"/usr/share/logstash/maxmind/GeoLite2-ASN.mmdb"}
[2022-07-22T22:03:29,693][INFO ][logstash.filters.geoip.databasemanager][main] GeoIP database path is configured manually so the plugin will not check for update. Keep in mind that if you are not using the database shipped with this plugin, please go to https://www.maxmind.com/en/geolite2/eula and understand the terms and conditions.
[2022-07-22T22:03:29,693][INFO ][logstash.filters.geoip ][main] Using geoip database {:path=>"/usr/share/logstash/maxmind/GeoLite2-City.mmdb"}
[2022-07-22T22:03:29,694][INFO ][logstash.filters.geoip.databasemanager][main] GeoIP database path is configured manually so the plugin will not check for update. Keep in mind that if you are not using the database shipped with this plugin, please go to https://www.maxmind.com/en/geolite2/eula and understand the terms and conditions.
[2022-07-22T22:03:29,694][INFO ][logstash.filters.geoip ][main] Using geoip database {:path=>"/usr/share/logstash/maxmind/GeoLite2-City.mmdb"}
[2022-07-22T22:03:29,695][INFO ][logstash.filters.geoip.databasemanager][main] GeoIP database path is configured manually so the plugin will not check for update. Keep in mind that if you are not using the database shipped with this plugin, please go to https://www.maxmind.com/en/geolite2/eula and understand the terms and conditions.
[2022-07-22T22:03:29,695][INFO ][logstash.filters.geoip ][main] Using geoip database {:path=>"/usr/share/logstash/maxmind/GeoLite2-City.mmdb"}
[2022-07-22T22:03:29,695][INFO ][logstash.filters.geoip.databasemanager][main] GeoIP database path is configured manually so the plugin will not check for update. Keep in mind that if you are not using the database shipped with this plugin, please go to https://www.maxmind.com/en/geolite2/eula and understand the terms and conditions.
[2022-07-22T22:03:29,695][INFO ][logstash.filters.geoip ][main] Using geoip database {:path=>"/usr/share/logstash/maxmind/GeoLite2-ASN.mmdb"}
[2022-07-22T22:03:29,832][INFO ][logstash.filters.geoip.databasemanager][main] GeoIP database path is configured manually so the plugin will not check for update. Keep in mind that if you are not using the database shipped with this plugin, please go to https://www.maxmind.com/en/geolite2/eula and understand the terms and conditions.
[2022-07-22T22:03:29,832][INFO ][logstash.filters.geoip ][main] Using geoip database {:path=>"/usr/share/logstash/maxmind/GeoLite2-City.mmdb"}
[2022-07-22T22:03:29,834][INFO ][logstash.filters.geoip.databasemanager][main] GeoIP database path is configured manually so the plugin will not check for update. Keep in mind that if you are not using the database shipped with this plugin, please go to https://www.maxmind.com/en/geolite2/eula and understand the terms and conditions.
[2022-07-22T22:03:29,834][INFO ][logstash.filters.geoip ][main] Using geoip database {:path=>"/usr/share/logstash/maxmind/GeoLite2-City.mmdb"}
[2022-07-22T22:03:29,881][INFO ][logstash.javapipeline ][main] Starting pipeline {:pipeline_id=>"main", "pipeline.workers"=>12, "pipeline.batch.size"=>125, "pipeline.batch.delay"=>50, "pipeline.max_inflight"=>1500, "pipeline.sources"=>["/etc/logstash/conf.d/01_input_dnslogs.conf", "/etc/logstash/conf.d/02_input_proxylogs.conf", "/etc/logstash/conf.d/03_input_iplogs.conf", "/etc/logstash/conf.d/51_filter_dnslogs.conf", "/etc/logstash/conf.d/52_filter_proxylogs.conf", "/etc/logstash/conf.d/53_filter_iplogs.conf", "/etc/logstash/conf.d/99_output.conf"], :thread=>"#<Thread:0x4d9c9e45 run>"}
[2022-07-22T22:03:31,823][INFO ][logstash.javapipeline ][main] Pipeline Java execution initialization time {"seconds"=>1.94}
[2022-07-22T22:03:31,838][INFO ][logstash.inputs.s3 ][main] Registering {:bucket=>"cisco-managed-*******", :region=>"******"}
[2022-07-22T22:03:31,952][INFO ][logstash.inputs.s3 ][main] Registering {:bucket=>"cisco-managed-*******", :region=>"******"}
[2022-07-22T22:03:31,961][INFO ][logstash.inputs.s3 ][main] Registering {:bucket=>"cisco-managed-********", :region=>"******"}
[2022-07-22T22:03:31,970][INFO ][logstash.javapipeline ][main] Pipeline started {"pipeline.id"=>"main"}
[2022-07-22T22:03:31,989][INFO ][logstash.inputs.s3 ][main][468c429eca8dd78eebdededa5ace043f0453472ea3fba4ebbe5f12a9c79157e1] Using default generated file for the sincedb {:filename=>"/var/lib/logstash/plugins/inputs/s3/sincedb_1be05263bc0fb504884d9860942b5f01"}
[2022-07-22T22:03:31,991][INFO ][logstash.inputs.s3 ][main][febfd5b152196b1756ad2b0a7db18570d3a1ef1ee0ba82b4ce87dd4ce6aa0f40] Using default generated file for the sincedb {:filename=>"/var/lib/logstash/plugins/inputs/s3/sincedb_cc72d6a45356caa18eac5393d6c9f68c"}
[2022-07-22T22:03:31,991][INFO ][logstash.inputs.s3 ][main][bd2a85a59fffcade0bd0fb5d4f09c8f575ade2a8b338f6ebe85ff380e3992dac] Using default generated file for the sincedb {:filename=>"/var/lib/logstash/plugins/inputs/s3/sincedb_91dafa8ad9874faca39520059022a500"}
[2022-07-22T22:03:32,019][INFO ][logstash.agent ] Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
[2022-07-22T22:03:33,013][INFO ][logstash.inputs.s3 ][main][bd2a85a59fffcade0bd0fb5d4f09c8f575ade2a8b338f6ebe85ff380e3992dac] No files found in bucket {:prefix=>"6159501_f5ac0eb9cfe7d0cb2b04bdf98b066b670a38b763/iplogs/"}
[2022-07-22T22:03:34,708][WARN ][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"https://logstash:xxxxxx@*************.es.europe-west2.gcp.elastic-cloud.com:9243/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :message=>"Got response code '401' contacting Elasticsearch at URL 'https://*************.es.europe-west2.gcp.elastic-cloud.com:9243/'"}
[2022-07-22T22:03:39,859][WARN ][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"https://logstash:xxxxxx@*************.es.europe-west2.gcp.elastic-cloud.com:9243/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :message=>"Got response code '401' contacting Elasticsearch at URL 'https://*************.es.europe-west2.gcp.elastic-cloud.com:9243/'"}
[2022-07-22T22:03:42,194][WARN ][logstash.runner ] SIGTERM received. Shutting down.
[2022-07-22T22:03:44,995][WARN ][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"https://logstash:xxxxxx@*************.es.europe-west2.gcp.elastic-cloud.com:9243/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :message=>"Got response code '401' contacting Elasticsearch at URL 'https://*************.es.europe-west2.gcp.elastic-cloud.com:9243/'"}
[2022-07-22T22:03:47,324][ERROR][org.logstash.execution.ShutdownWatcherExt] The shutdown process appears to be stalled due to busy or blocked plugins. Check the logs for more information.
[2022-07-22T22:03:47,325][INFO ][org.logstash.execution.ShutdownWatcherExt] The queue is draining before shutdown.
[2022-07-22T22:03:50,143][WARN ][logstash.outputs.elasticsearch][main] Attempted to resurrect connection to dead ES instance, but got an error {:url=>"https://logstash:xxxxxx@*************.es.europe-west2.gcp.elastic-cloud.com:9243/", :exception=>LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :message=>"Got response code '401' contacting Elasticsearch at URL 'https://*************.es.europe-west2.gcp.elastic-cloud.com:9243/'"}