filebeat.autodiscover:
providers:
- type: kubernetes
hints.enabled: true
json.message_key: message
json.timestamp.key: timestamp
json.keys_under_root: true
json.overwrite_keys: true
fields_under_root: true
hints.default_config:
type: container
paths:
- /var/log/oauth-apiserver/*.log
- /var/log/kube-apiserver/*.log
- /var/log/openshift-apiserver/*.log
- /var/log/oauth-server/*.log
- /var/log/audit/*.log
processors:
- add_kubernetes_metadata:
host: ${NODE_NAME}
matchers:
- logs_path:
logs_path: "/var/log/*/"
I keep running into this parsing error on openshift.
image: docker.elastic.co/beats/filebeat:8.8.2
{"log.level":"error","@timestamp":"2023-07-21T02:59:37.753Z","log.logger":"reader_docker_json","log.origin":{"file.name":"readjson/docker_json.go","file.line":231},"message":"Parse line error: parsing docker timestamp: parsing time \"\" as \"2006-01-02T15:04:05Z07:00\": cannot parse \"\" as \"2006\"","service.name":"filebeat","ecs.version":"1.6.0"}
{"log.level":"error","@timestamp":"2023-07-21T02:59:37.753Z","log.logger":"reader_docker_json","log.origin":{"file.name":"readjson/docker_json.go","file.line":231},"message":"Parse line error: parsing docker timestamp: parsing time \"\" as \"2006-01-02T15:04:05Z07:00\": cannot parse \"\" as \"2006\"","service.name":"filebeat","ecs.version":"1.6.0"}
{"log.level":"error","@timestamp":"2023-07-21T02:59:37.753Z","log.logger":"reader_docker_json","log.origin":{"file.name":"readjson/docker_json.go","file.line":231},"message":"Parse line error: parsing docker timestamp: parsing time \"\" as \"2006-01-02T15:04:05Z07:00\": cannot parse \"\" as \"2006\"","service.name":"filebeat","ecs.version":"1.6.0"}
Any help or pointers will be appreciated.