Hi there, i am really confused why changing my 10-syslog-filter.conf file caused i/o timeout event on all the clients and no data was saved. Initial config is:
Then i changed on line if [type] == "log" that broke everything. The reason i changed it to log is because i can see my data collected on the client is marked and type=log thus i was hoping it will apply my filter and parse the way i need it. Maybe i am doing something wrong. Thank you in advance.
Did you update any plugins? I didn't update any plugins but i updated all the ELK components from 2. version to 5.6.2
Did the if block where [type] == "syslog" ever get executed? It doesn't look like. I have seen it being executed once when i changed type to LOG but then it worked for a day and broke with i/o timeout events on the clients. Also it looks to me if i set TYPE=SYSLOG it parses it with some sort of default filter and not the one that i specify in my filter file
What is your input config? Here is my input config
I can't really understand what causing clients to fail. All the other configurations are pretty much standard. Here is my filebeat config just in case:
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.