diff --git a/CHANGELOG.asciidoc b/CHANGELOG.asciidoc index eea6a4717a1..d10da163f07 100644 --- a/CHANGELOG.asciidoc +++ b/CHANGELOG.asciidoc @@ -121,6 +121,7 @@ https://github.com/elastic/beats/compare/v6.4.0...master[Check the HEAD diff] - Add tag "multiline" to "log.flags" if event consists of multiple lines. {pull}7997[7997] - Add haproxy module. {pull}8014[8014] - Release `docker` input as GA. {pull}8328[8328] +- Keep original messages in case of Filebeat modules. {pull}8448[8448] *Heartbeat* diff --git a/filebeat/_meta/fields.common.yml b/filebeat/_meta/fields.common.yml index 930e0f67f90..aedfc08cf91 100644 --- a/filebeat/_meta/fields.common.yml +++ b/filebeat/_meta/fields.common.yml @@ -112,6 +112,12 @@ description: > This field contains the flags of the event. + - name: log.original + type: keyword + description: > + The unprocessed original log message. This can be used for reprocessing logs. + index: false + - name: event.created type: date description: > diff --git a/filebeat/channel/factory.go b/filebeat/channel/factory.go index 86db045c84f..0825bd5f5ab 100644 --- a/filebeat/channel/factory.go +++ b/filebeat/channel/factory.go @@ -43,6 +43,9 @@ type clientEventer struct { // inputOutletConfig defines common input settings // for the publisher pipeline. type inputOutletConfig struct { + // KeepOriginalMsg determines if the original message needs to be kept for a module. + KeepOriginalMsg bool `config:"keep_original_message"` + // event processing common.EventMetadata `config:",inline"` // Fields and tags to add to events. Processors processors.PluginConfig `config:"processors"` @@ -59,6 +62,10 @@ type inputOutletConfig struct { } +var defaultConfig = inputOutletConfig{ + KeepOriginalMsg: true, +} + // NewOutletFactory creates a new outlet factory for // connecting an input to the publisher pipeline. func NewOutletFactory( @@ -82,7 +89,7 @@ func NewOutletFactory( // This guarantees ordering between events as required by the registrar for // file.State updates func (f *OutletFactory) Create(p beat.Pipeline, cfg *common.Config, dynFields *common.MapStrPointer) (Outleter, error) { - config := inputOutletConfig{} + config := defaultConfig if err := cfg.Unpack(&config); err != nil { return nil, err } @@ -101,6 +108,7 @@ func (f *OutletFactory) Create(p beat.Pipeline, cfg *common.Config, dynFields *c meta := common.MapStr{} setMeta(meta, "pipeline", config.Pipeline) + keepOriginal := false fields := common.MapStr{} setMeta(fields, "module", config.Module) setMeta(fields, "name", config.Fileset) @@ -108,6 +116,8 @@ func (f *OutletFactory) Create(p beat.Pipeline, cfg *common.Config, dynFields *c fields = common.MapStr{ "fileset": fields, } + keepOriginal = config.KeepOriginalMsg + } if config.Type != "" { fields["prospector"] = common.MapStr{ @@ -119,13 +129,14 @@ func (f *OutletFactory) Create(p beat.Pipeline, cfg *common.Config, dynFields *c } client, err := p.ConnectWith(beat.ClientConfig{ - PublishMode: beat.GuaranteedSend, - EventMetadata: config.EventMetadata, - DynamicFields: dynFields, - Meta: meta, - Fields: fields, - Processor: processors, - Events: f.eventer, + PublishMode: beat.GuaranteedSend, + EventMetadata: config.EventMetadata, + DynamicFields: dynFields, + Meta: meta, + Fields: fields, + KeepOriginalMsg: keepOriginal, + Processor: processors, + Events: f.eventer, }) if err != nil { return nil, err diff --git a/filebeat/docs/fields.asciidoc b/filebeat/docs/fields.asciidoc index 399928d810f..a876789827e 100644 --- a/filebeat/docs/fields.asciidoc +++ b/filebeat/docs/fields.asciidoc @@ -3042,6 +3042,18 @@ Logging level. This field contains the flags of the event. +-- + +*`log.original`*:: ++ +-- +type: keyword + +The unprocessed original log message. This can be used for reprocessing logs. + + +Field is not indexed. + -- *`event.created`*:: diff --git a/filebeat/filebeat.reference.yml b/filebeat/filebeat.reference.yml index c91b2eb8a72..a6ae640e5ae 100644 --- a/filebeat/filebeat.reference.yml +++ b/filebeat/filebeat.reference.yml @@ -27,6 +27,8 @@ filebeat.modules: # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true # Authorization logs #auth: @@ -42,6 +44,8 @@ filebeat.modules: # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true #------------------------------- Apache2 Module ------------------------------ #- module: apache2 @@ -56,6 +60,8 @@ filebeat.modules: # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true # Error logs #error: @@ -68,6 +74,8 @@ filebeat.modules: # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true #------------------------------- Auditd Module ------------------------------- #- module: auditd @@ -81,6 +89,8 @@ filebeat.modules: # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true #---------------------------- elasticsearch Module --------------------------- - module: elasticsearch @@ -142,6 +152,8 @@ filebeat.modules: # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true # Debug logs #debug: @@ -154,6 +166,8 @@ filebeat.modules: # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true # Startup logs #startup: @@ -166,6 +180,8 @@ filebeat.modules: # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true #--------------------------------- IIS Module -------------------------------- #- module: iis @@ -180,6 +196,8 @@ filebeat.modules: # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true # Error logs #error: @@ -192,6 +210,8 @@ filebeat.modules: # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true #-------------------------------- Kafka Module ------------------------------- - module: kafka @@ -250,6 +270,8 @@ filebeat.modules: # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true #-------------------------------- MySQL Module ------------------------------- #- module: mysql @@ -264,6 +286,8 @@ filebeat.modules: # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true # Slow logs #slowlog: @@ -276,6 +300,8 @@ filebeat.modules: # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true #-------------------------------- Nginx Module ------------------------------- #- module: nginx @@ -290,6 +316,8 @@ filebeat.modules: # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true # Error logs #error: @@ -302,6 +330,8 @@ filebeat.modules: # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true #------------------------------- Osquery Module ------------------------------ - module: osquery @@ -330,6 +360,8 @@ filebeat.modules: # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true #-------------------------------- Redis Module ------------------------------- #- module: redis @@ -364,6 +396,8 @@ filebeat.modules: # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true #=========================== Filebeat inputs ============================= diff --git a/filebeat/include/fields.go b/filebeat/include/fields.go index c3c862b6682..bff2cdc5d10 100644 --- a/filebeat/include/fields.go +++ b/filebeat/include/fields.go @@ -31,5 +31,5 @@ func init() { // Asset returns asset data func Asset() string { - return "" + return "" } diff --git a/filebeat/module/apache2/_meta/config.reference.yml b/filebeat/module/apache2/_meta/config.reference.yml index ad61cd6f5f1..6667cb4428c 100644 --- a/filebeat/module/apache2/_meta/config.reference.yml +++ b/filebeat/module/apache2/_meta/config.reference.yml @@ -10,6 +10,8 @@ # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true # Error logs #error: @@ -22,3 +24,5 @@ # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true diff --git a/filebeat/module/apache2/access/test/test.log-expected.json b/filebeat/module/apache2/access/test/test.log-expected.json index a8fbd26c0a2..e5062e0af46 100644 --- a/filebeat/module/apache2/access/test/test.log-expected.json +++ b/filebeat/module/apache2/access/test/test.log-expected.json @@ -11,6 +11,7 @@ "fileset.module": "apache2", "fileset.name": "access", "input.type": "log", + "log.original": "::1 - - [26/Dec/2016:16:16:29 +0200] \"GET /favicon.ico HTTP/1.1\" 404 209", "offset": 0, "prospector.type": "log" }, @@ -36,6 +37,7 @@ "fileset.module": "apache2", "fileset.name": "access", "input.type": "log", + "log.original": "192.168.33.1 - - [26/Dec/2016:16:22:13 +0000] \"GET /hello HTTP/1.1\" 404 499 \"-\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:50.0) Gecko/20100101 Firefox/50.0\"", "offset": 73, "prospector.type": "log" }, @@ -47,6 +49,7 @@ "fileset.module": "apache2", "fileset.name": "access", "input.type": "log", + "log.original": "::1 - - [26/Dec/2016:16:16:48 +0200] \"-\" 408 -", "offset": 238, "prospector.type": "log" }, @@ -71,6 +74,7 @@ "fileset.module": "apache2", "fileset.name": "access", "input.type": "log", + "log.original": "172.17.0.1 - - [29/May/2017:19:02:48 +0000] \"GET /stringpatch HTTP/1.1\" 404 612 \"-\" \"Mozilla/5.0 (Windows NT 6.1; rv:15.0) Gecko/20120716 Firefox/15.0a2\" \"-\"", "offset": 285, "prospector.type": "log" } diff --git a/filebeat/module/apache2/error/test/test.log-expected.json b/filebeat/module/apache2/error/test/test.log-expected.json index 96d61106465..2ff1401fb3c 100644 --- a/filebeat/module/apache2/error/test/test.log-expected.json +++ b/filebeat/module/apache2/error/test/test.log-expected.json @@ -7,6 +7,7 @@ "fileset.module": "apache2", "fileset.name": "error", "input.type": "log", + "log.original": "[Mon Dec 26 16:22:08 2016] [error] [client 192.168.33.1] File does not exist: /var/www/favicon.ico", "offset": 0, "prospector.type": "log" }, @@ -19,6 +20,7 @@ "fileset.module": "apache2", "fileset.name": "error", "input.type": "log", + "log.original": "[Mon Dec 26 16:15:55.103786 2016] [core:notice] [pid 11379] AH00094: Command line: '/usr/local/Cellar/httpd24/2.4.23_2/bin/httpd'", "offset": 99, "prospector.type": "log" }, @@ -33,6 +35,7 @@ "fileset.module": "apache2", "fileset.name": "error", "input.type": "log", + "log.original": "[Fri Sep 09 10:42:29.902022 2011] [core:error] [pid 35708:tid 4328636416] [client 72.15.99.187] File does not exist: /usr/local/apache2/htdocs/favicon.ico", "offset": 229, "prospector.type": "log" } diff --git a/filebeat/module/auditd/_meta/config.reference.yml b/filebeat/module/auditd/_meta/config.reference.yml index 57776242584..af33a43204a 100644 --- a/filebeat/module/auditd/_meta/config.reference.yml +++ b/filebeat/module/auditd/_meta/config.reference.yml @@ -9,3 +9,5 @@ # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true diff --git a/filebeat/module/auditd/log/test/test.log-expected.json b/filebeat/module/auditd/log/test/test.log-expected.json index 4b63b828497..16ff3626a86 100644 --- a/filebeat/module/auditd/log/test/test.log-expected.json +++ b/filebeat/module/auditd/log/test/test.log-expected.json @@ -14,6 +14,7 @@ "fileset.module": "auditd", "fileset.name": "log", "input.type": "log", + "log.original": "type=MAC_IPSEC_EVENT msg=audit(1485893834.891:18877201): op=SPD-delete auid=4294967295 ses=4294967295 res=1 src=192.168.2.0 src_prefixlen=24 dst=192.168.0.0 dst_prefixlen=16", "offset": 0, "prospector.type": "log" }, @@ -48,6 +49,7 @@ "fileset.module": "auditd", "fileset.name": "log", "input.type": "log", + "log.original": "type=SYSCALL msg=audit(1485893834.891:18877199): arch=c000003e syscall=44 success=yes exit=184 a0=9 a1=7f564b2672a0 a2=b8 a3=0 items=0 ppid=1240 pid=1281 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=\"charon\" exe=2F7573722F6C6962657865632F7374726F6E677377616E2F636861726F6E202864656C6574656429 key=(null)", "offset": 174, "prospector.type": "log" } diff --git a/filebeat/module/elasticsearch/audit/test/test.log-expected.json b/filebeat/module/elasticsearch/audit/test/test.log-expected.json index 77948ecc89f..865c14ca5e6 100644 --- a/filebeat/module/elasticsearch/audit/test/test.log-expected.json +++ b/filebeat/module/elasticsearch/audit/test/test.log-expected.json @@ -9,6 +9,7 @@ "fileset.module": "elasticsearch", "fileset.name": "audit", "input.type": "log", + "log.original": "[2018-06-19T05:16:15,549] [rest] [authentication_failed] origin_address=[147.107.128.77], principal=[i030648], uri=[/_xpack/security/_authenticate]", "message": "[2018-06-19T05:16:15,549] [rest] [authentication_failed] origin_address=[147.107.128.77], principal=[i030648], uri=[/_xpack/security/_authenticate]", "offset": 0, "prospector.type": "log", @@ -25,6 +26,7 @@ "fileset.module": "elasticsearch", "fileset.name": "audit", "input.type": "log", + "log.original": "[2018-06-19T05:07:52,304] [v_VJhjV] [rest] [authentication_failed]\torigin_address=[172.22.0.3], principal=[rado], uri=[/_xpack/security/_authenticate]", "message": "[2018-06-19T05:07:52,304] [v_VJhjV] [rest] [authentication_failed]\torigin_address=[172.22.0.3], principal=[rado], uri=[/_xpack/security/_authenticate]", "offset": 155, "prospector.type": "log", @@ -42,6 +44,7 @@ "fileset.module": "elasticsearch", "fileset.name": "audit", "input.type": "log", + "log.original": "[2018-06-19T05:00:15,778] [transport] [access_granted] origin_type=[local_node], origin_address=[192.168.1.165], principal=[_xpack_security], action=[indices:data/read/scroll/clear], request=[ClearScrollRequest]", "message": "[2018-06-19T05:00:15,778] [transport] [access_granted] origin_type=[local_node], origin_address=[192.168.1.165], principal=[_xpack_security], action=[indices:data/read/scroll/clear], request=[ClearScrollRequest]", "offset": 306, "prospector.type": "log", @@ -57,6 +60,7 @@ "fileset.module": "elasticsearch", "fileset.name": "audit", "input.type": "log", + "log.original": "[2018-06-19T05:07:45,544] [v_VJhjV] [rest] [anonymous_access_denied]\torigin_address=[172.22.0.3], uri=[/_xpack/security/_authenticate]", "message": "[2018-06-19T05:07:45,544] [v_VJhjV] [rest] [anonymous_access_denied]\torigin_address=[172.22.0.3], uri=[/_xpack/security/_authenticate]", "offset": 519, "prospector.type": "log", @@ -72,6 +76,7 @@ "fileset.module": "elasticsearch", "fileset.name": "audit", "input.type": "log", + "log.original": "[2018-06-19T05:26:27,268] [rest] [authentication_failed]\torigin_address=[147.107.128.77], principal=[N078801], uri=[/_xpack/security/_authenticate]", "message": "[2018-06-19T05:26:27,268] [rest] [authentication_failed]\torigin_address=[147.107.128.77], principal=[N078801], uri=[/_xpack/security/_authenticate]", "offset": 654, "prospector.type": "log", @@ -89,6 +94,7 @@ "fileset.module": "elasticsearch", "fileset.name": "audit", "input.type": "log", + "log.original": "[2018-06-19T05:55:26,898] [transport] [access_denied]\torigin_type=[rest], origin_address=[147.107.128.77], principal=[_anonymous], action=[cluster:monitor/main], request=[MainRequest]", "message": "[2018-06-19T05:55:26,898] [transport] [access_denied]\torigin_type=[rest], origin_address=[147.107.128.77], principal=[_anonymous], action=[cluster:monitor/main], request=[MainRequest]", "offset": 802, "prospector.type": "log", @@ -106,6 +112,7 @@ "fileset.module": "elasticsearch", "fileset.name": "audit", "input.type": "log", + "log.original": "[2018-06-19T05:24:15,190] [v_VJhjV] [rest] [authentication_failed]\torigin_address=[172.18.0.3], principal=[elastic], uri=[/_nodes?filter_path=nodes.*.version%2Cnodes.*.http.publish_address%2Cnodes.*.ip], request_body=[body]", "message": "[2018-06-19T05:24:15,190] [v_VJhjV] [rest] [authentication_failed]\torigin_address=[172.18.0.3], principal=[elastic], uri=[/_nodes?filter_path=nodes.*.version%2Cnodes.*.http.publish_address%2Cnodes.*.ip], request_body=[body]", "offset": 986, "prospector.type": "log", diff --git a/filebeat/module/elasticsearch/gc/test/test.log-expected.json b/filebeat/module/elasticsearch/gc/test/test.log-expected.json index c9d0621afc9..aa32d790c77 100644 --- a/filebeat/module/elasticsearch/gc/test/test.log-expected.json +++ b/filebeat/module/elasticsearch/gc/test/test.log-expected.json @@ -14,6 +14,7 @@ "fileset.module": "elasticsearch", "fileset.name": "gc", "input.type": "log", + "log.original": "2018-03-03T19:37:06.157+0500: 14597.826: [GC (CMS Initial Mark) [1 CMS-initial-mark: 131804K(174784K)] 142444K(253440K), 0.0021716 secs] [Times: user=0.01 sys=0.00, real=0.00 secs]", "message": "2018-03-03T19:37:06.157+0500: 14597.826: [GC (CMS Initial Mark) [1 CMS-initial-mark: 131804K(174784K)] 142444K(253440K), 0.0021716 secs] [Times: user=0.01 sys=0.00, real=0.00 secs]", "offset": 0, "prospector.type": "log", @@ -27,6 +28,7 @@ "fileset.module": "elasticsearch", "fileset.name": "gc", "input.type": "log", + "log.original": "2018-06-11T01:53:11.382+0000: 1396138.752: Total time for which application threads were stopped: 0.0083760 seconds, Stopping threads took: 0.0000702 seconds", "message": "2018-06-11T01:53:11.382+0000: 1396138.752: Total time for which application threads were stopped: 0.0083760 seconds, Stopping threads took: 0.0000702 seconds", "offset": 181, "prospector.type": "log", @@ -54,6 +56,7 @@ "fileset.module": "elasticsearch", "fileset.name": "gc", "input.type": "log", + "log.original": "2018-06-30T16:35:26.632+0500: 224.671: [GC (CMS Final Remark) [YG occupancy: 113198 K (157248 K)]224.671: [Rescan (parallel) , 0.0148273 secs]224.686: [weak refs processing, 0.0003647 secs]224.687: [class unloading, 0.0188407 secs]224.705: [scrub symbol table, 0.0100207 secs]224.715: [scrub string table, 0.0005253 secs][1 CMS-remark: 277821K(349568K)] 391020K(506816K), 0.0457689 secs] [Times: user=0.12 sys=0.00, real=0.04 secs]", "message": "2018-06-30T16:35:26.632+0500: 224.671: [GC (CMS Final Remark) [YG occupancy: 113198 K (157248 K)]224.671: [Rescan (parallel) , 0.0148273 secs]224.686: [weak refs processing, 0.0003647 secs]224.687: [class unloading, 0.0188407 secs]224.705: [scrub symbol table, 0.0100207 secs]224.715: [scrub string table, 0.0005253 secs][1 CMS-remark: 277821K(349568K)] 391020K(506816K), 0.0457689 secs] [Times: user=0.12 sys=0.00, real=0.04 secs]", "offset": 339, "prospector.type": "log", diff --git a/filebeat/module/elasticsearch/server/test/test.log-expected.json b/filebeat/module/elasticsearch/server/test/test.log-expected.json index f53a28cf9fb..7aedf186e11 100644 --- a/filebeat/module/elasticsearch/server/test/test.log-expected.json +++ b/filebeat/module/elasticsearch/server/test/test.log-expected.json @@ -8,6 +8,7 @@ "fileset.name": "server", "input.type": "log", "log.level": "INFO", + "log.original": "[2018-05-17T08:29:12,177][INFO ][o.e.c.m.MetaDataCreateIndexService] [vWNJsZ3] [test-filebeat-modules] creating index, cause [auto(bulk api)], templates [test-filebeat-modules], shards [5]/[1], mappings [doc]", "message": "creating index, cause [auto(bulk api)], templates [test-filebeat-modules], shards [5]/[1], mappings [doc]", "offset": 0, "prospector.type": "log", @@ -21,6 +22,7 @@ "fileset.name": "server", "input.type": "log", "log.level": "INFO", + "log.original": "[2018-05-17T08:19:35,939][INFO ][o.e.n.Node ] [] initializing ...", "message": "initializing ...", "offset": 209, "prospector.type": "log", @@ -34,6 +36,7 @@ "fileset.name": "server", "input.type": "log", "log.level": "INFO", + "log.original": "[2018-05-17T08:19:36,089][INFO ][o.e.e.NodeEnvironment ] [vWNJsZ3] using [1] data paths, mounts [[/ (/dev/disk1s1)]], net usable_space [32.4gb], net total_space [233.5gb], types [apfs]", "message": "using [1] data paths, mounts [[/ (/dev/disk1s1)]], net usable_space [32.4gb], net total_space [233.5gb], types [apfs]", "offset": 289, "prospector.type": "log", @@ -47,6 +50,7 @@ "fileset.name": "server", "input.type": "log", "log.level": "INFO", + "log.original": "[2018-05-17T08:19:36,090][INFO ][o.e.e.NodeEnvironment ] [vWNJsZ3] heap size [990.7mb], compressed ordinary object pointers [true]", "message": "heap size [990.7mb], compressed ordinary object pointers [true]", "offset": 477, "prospector.type": "log", @@ -59,6 +63,7 @@ "fileset.name": "server", "input.type": "log", "log.level": "INFO", + "log.original": "[2018-05-17T08:19:36,116][INFO ][o.e.n.Node ] node name [vWNJsZ3] derived from node ID [vWNJsZ3nTIKh5a1ai-ftYQ]; set [node.name] to override", "message": "node name [vWNJsZ3] derived from node ID [vWNJsZ3nTIKh5a1ai-ftYQ]; set [node.name] to override", "offset": 611, "prospector.type": "log", @@ -72,6 +77,7 @@ "fileset.name": "server", "input.type": "log", "log.level": "INFO", + "log.original": "[2018-05-17T08:23:48,941][INFO ][o.e.c.r.a.DiskThresholdMonitor] [vWNJsZ3] low disk watermark [85%] exceeded on [vWNJsZ3nTIKh5a1ai-ftYQ][vWNJsZ3][/Users/ruflin/Downloads/elasticsearch-6.2.4/data/nodes/0] free: 33.4gb[14.3%], replicas will not be assigned to this node", "message": "low disk watermark [85%] exceeded on [vWNJsZ3nTIKh5a1ai-ftYQ][vWNJsZ3][/Users/ruflin/Downloads/elasticsearch-6.2.4/data/nodes/0] free: 33.4gb[14.3%], replicas will not be assigned to this node", "offset": 766, "prospector.type": "log", @@ -86,6 +92,7 @@ "fileset.name": "server", "input.type": "log", "log.level": "INFO", + "log.original": "[2018-05-17T08:29:09,245][INFO ][o.e.c.m.MetaDataCreateIndexService] [vWNJsZ3] [filebeat-test-input] creating index, cause [auto(bulk api)], templates [filebeat-test-input], shards [5]/[1], mappings [doc]", "message": "creating index, cause [auto(bulk api)], templates [filebeat-test-input], shards [5]/[1], mappings [doc]", "offset": 1034, "prospector.type": "log", @@ -101,6 +108,7 @@ "fileset.name": "server", "input.type": "log", "log.level": "INFO", + "log.original": "[2018-05-17T08:29:09,576][INFO ][o.e.c.m.MetaDataMappingService] [vWNJsZ3] [filebeat-test-input/aOGgDwbURfCV57AScqbCgw] update_mapping [doc]", "message": "update_mapping [doc]", "offset": 1239, "prospector.type": "log", @@ -116,6 +124,7 @@ "fileset.name": "server", "input.type": "log", "log.level": "INFO", + "log.original": "[2018-07-09T12:47:33,959][INFO ][o.e.c.m.MetaDataMappingService] [QGY1F5P] [.kibana/3tWftqb4RLKdyCAga9syGA] update_mapping [doc]", "message": "update_mapping [doc]", "offset": 1380, "prospector.type": "log", @@ -129,6 +138,7 @@ "fileset.name": "server", "input.type": "log", "log.level": "INFO", + "log.original": "[2018-05-17T08:29:25,598][INFO ][o.e.n.Node ] [vWNJsZ3] closing ...", "message": "closing ...", "offset": 1509, "prospector.type": "log", @@ -142,6 +152,7 @@ "fileset.name": "server", "input.type": "log", "log.level": "INFO", + "log.original": "[2018-05-17T08:29:25,612][INFO ][o.e.n.Node ] [vWNJsZ3] closed", "message": "closed", "offset": 1591, "prospector.type": "log", @@ -155,6 +166,7 @@ "fileset.name": "server", "input.type": "log", "log.level": "INFO", + "log.original": "[2018-07-03T11:45:48,548][INFO ][o.e.d.z.ZenDiscovery ] [srvmulpvlsk252_md] master_left [{srvmulpvlsk250_md}{igrwSoPGSJ6u_5b8k26tgQ}{PuRqciBFRbiQvL2_lS7LrQ}{srvmulpvlsk250.loganalytics.santanderuk.corp}{180.39.9.91:9300}{ml.max_open_jobs=10, ml.enabled=true}], reason [failed to ping, tried [3] times, each with maximum [30s] timeout]", "message": "master_left [{srvmulpvlsk250_md}{igrwSoPGSJ6u_5b8k26tgQ}{PuRqciBFRbiQvL2_lS7LrQ}{srvmulpvlsk250.loganalytics.santanderuk.corp}{180.39.9.91:9300}{ml.max_open_jobs=10, ml.enabled=true}], reason [failed to ping, tried [3] times, each with maximum [30s] timeout]", "offset": 1668, "prospector.type": "log", @@ -171,6 +183,7 @@ "multiline" ], "log.level": "WARN", + "log.original": "[2018-07-03T11:45:48,548][WARN ][o.e.d.z.ZenDiscovery ] [srvmulpvlsk252_md] master left (reason = failed to ping, tried [3] times, each with maximum [30s] timeout), current nodes: nodes:\n {srvmulpvlsk252_md}{uc5xdiQgRhaBIY-sszgjvQ}{X9pC0t1UQQix_NNOM0J6JQ}{srvmulpvlsk252.loganalytics.santanderuk.corp}{180.39.9.93:9300}{ml.max_open_jobs=10, ml.enabled=true}, local\n {srvmulpvlsk258_md}{HgW6EDn5QCmWVmICy4saHw}{o8zku7OJR4CTp0IjY8Ag4Q}{srvmulpvlsk258.loganalytics.santanderuk.corp}{180.39.9.99:9300}{ml.max_open_jobs=10, ml.enabled=true}\n {srvmulpvlsk250_md}{igrwSoPGSJ6u_5b8k26tgQ}{PuRqciBFRbiQvL2_lS7LrQ}{srvmulpvlsk250.loganalytics.santanderuk.corp}{180.39.9.91:9300}{ml.max_open_jobs=10, ml.enabled=true}, master\n {srvmulpvlsk254_id}{wZYeAh2URc2NwBIHZolLWQ}{3nduupo-TzSPaXjQaNu4Sg}{srvmulpvlsk254.loganalytics.santanderuk.corp}{180.39.9.95:9300}{ml.max_open_jobs=10, ml.enabled=true}", "message": "master left (reason = failed to ping, tried [3] times, each with maximum [30s] timeout), current nodes: nodes:\n {srvmulpvlsk252_md}{uc5xdiQgRhaBIY-sszgjvQ}{X9pC0t1UQQix_NNOM0J6JQ}{srvmulpvlsk252.loganalytics.santanderuk.corp}{180.39.9.93:9300}{ml.max_open_jobs=10, ml.enabled=true}, local\n {srvmulpvlsk258_md}{HgW6EDn5QCmWVmICy4saHw}{o8zku7OJR4CTp0IjY8Ag4Q}{srvmulpvlsk258.loganalytics.santanderuk.corp}{180.39.9.99:9300}{ml.max_open_jobs=10, ml.enabled=true}\n {srvmulpvlsk250_md}{igrwSoPGSJ6u_5b8k26tgQ}{PuRqciBFRbiQvL2_lS7LrQ}{srvmulpvlsk250.loganalytics.santanderuk.corp}{180.39.9.91:9300}{ml.max_open_jobs=10, ml.enabled=true}, master\n {srvmulpvlsk254_id}{wZYeAh2URc2NwBIHZolLWQ}{3nduupo-TzSPaXjQaNu4Sg}{srvmulpvlsk254.loganalytics.santanderuk.corp}{180.39.9.95:9300}{ml.max_open_jobs=10, ml.enabled=true}", "offset": 2008, "prospector.type": "log", @@ -186,6 +199,7 @@ "multiline" ], "log.level": "WARN", + "log.original": "[2018-07-03T11:45:52,666][WARN ][r.suppressed ] path: /_xpack/monitoring/_bulk, params: {system_id=logstash, system_api_version=2, interval=1s}\norg.elasticsearch.cluster.block.ClusterBlockException: blocked by: [SERVICE_UNAVAILABLE/2/no master];\n at org.elasticsearch.cluster.block.ClusterBlocks.globalBlockedException(ClusterBlocks.java:165) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.cluster.block.ClusterBlocks.globalBlockedRaiseException(ClusterBlocks.java:151) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.xpack.monitoring.action.TransportMonitoringBulkAction.doExecute(TransportMonitoringBulkAction.java:57) ~[?:?]\n at org.elasticsearch.xpack.monitoring.action.TransportMonitoringBulkAction.doExecute(TransportMonitoringBulkAction.java:40) ~[?:?]\n at org.elasticsearch.action.support.TransportAction.doExecute(TransportAction.java:146) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.action.support.TransportAction$RequestFilterChain.proceed(TransportAction.java:170) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.xpack.security.action.filter.SecurityActionFilter.lambda$apply$1(SecurityActionFilter.java:133) ~[?:?]\n at org.elasticsearch.action.ActionListener$1.onResponse(ActionListener.java:59) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.xpack.security.action.filter.SecurityActionFilter.lambda$authorizeRequest$4(SecurityActionFilter.java:208) ~[?:?]\n at org.elasticsearch.xpack.security.authz.AuthorizationUtils$AsyncAuthorizer.maybeRun(AuthorizationUtils.java:127) ~[?:?]\n at org.elasticsearch.xpack.security.authz.AuthorizationUtils$AsyncAuthorizer.setRunAsRoles(AuthorizationUtils.java:121) ~[?:?]\n at org.elasticsearch.xpack.security.authz.AuthorizationUtils$AsyncAuthorizer.authorize(AuthorizationUtils.java:109) ~[?:?]\n at org.elasticsearch.xpack.security.action.filter.SecurityActionFilter.authorizeRequest(SecurityActionFilter.java:210) ~[?:?]\n at org.elasticsearch.xpack.security.action.filter.SecurityActionFilter.lambda$applyInternal$3(SecurityActionFilter.java:186) ~[?:?]\n at org.elasticsearch.action.ActionListener$1.onResponse(ActionListener.java:59) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.lambda$authenticateAsync$2(AuthenticationService.java:212) ~[?:?]\n at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.lambda$lookForExistingAuthentication$4(AuthenticationService.java:246) ~[?:?]\n at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.lookForExistingAuthentication(AuthenticationService.java:257) ~[?:?]\n at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.authenticateAsync(AuthenticationService.java:210) ~[?:?]\n at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.access$000(AuthenticationService.java:159) ~[?:?]\n at org.elasticsearch.xpack.security.authc.AuthenticationService.authenticate(AuthenticationService.java:122) ~[?:?]\n at org.elasticsearch.xpack.security.action.filter.SecurityActionFilter.applyInternal(SecurityActionFilter.java:185) ~[?:?]\n at org.elasticsearch.xpack.security.action.filter.SecurityActionFilter.apply(SecurityActionFilter.java:145) ~[?:?]\n at org.elasticsearch.action.support.TransportAction$RequestFilterChain.proceed(TransportAction.java:168) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.action.support.TransportAction.execute(TransportAction.java:142) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.action.support.TransportAction.execute(TransportAction.java:84) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.client.node.NodeClient.executeLocally(NodeClient.java:83) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.client.node.NodeClient.doExecute(NodeClient.java:72) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.client.support.AbstractClient.execute(AbstractClient.java:408) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.action.ActionRequestBuilder.execute(ActionRequestBuilder.java:80) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.xpack.monitoring.rest.action.RestMonitoringBulkAction.lambda$doPrepareRequest$0(RestMonitoringBulkAction.java:77) ~[?:?]\n at org.elasticsearch.rest.BaseRestHandler.handleReques", "message": "path: /_xpack/monitoring/_bulk, params: {system_id=logstash, system_api_version=2, interval=1s}\norg.elasticsearch.cluster.block.ClusterBlockException: blocked by: [SERVICE_UNAVAILABLE/2/no master];\n at org.elasticsearch.cluster.block.ClusterBlocks.globalBlockedException(ClusterBlocks.java:165) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.cluster.block.ClusterBlocks.globalBlockedRaiseException(ClusterBlocks.java:151) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.xpack.monitoring.action.TransportMonitoringBulkAction.doExecute(TransportMonitoringBulkAction.java:57) ~[?:?]\n at org.elasticsearch.xpack.monitoring.action.TransportMonitoringBulkAction.doExecute(TransportMonitoringBulkAction.java:40) ~[?:?]\n at org.elasticsearch.action.support.TransportAction.doExecute(TransportAction.java:146) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.action.support.TransportAction$RequestFilterChain.proceed(TransportAction.java:170) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.xpack.security.action.filter.SecurityActionFilter.lambda$apply$1(SecurityActionFilter.java:133) ~[?:?]\n at org.elasticsearch.action.ActionListener$1.onResponse(ActionListener.java:59) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.xpack.security.action.filter.SecurityActionFilter.lambda$authorizeRequest$4(SecurityActionFilter.java:208) ~[?:?]\n at org.elasticsearch.xpack.security.authz.AuthorizationUtils$AsyncAuthorizer.maybeRun(AuthorizationUtils.java:127) ~[?:?]\n at org.elasticsearch.xpack.security.authz.AuthorizationUtils$AsyncAuthorizer.setRunAsRoles(AuthorizationUtils.java:121) ~[?:?]\n at org.elasticsearch.xpack.security.authz.AuthorizationUtils$AsyncAuthorizer.authorize(AuthorizationUtils.java:109) ~[?:?]\n at org.elasticsearch.xpack.security.action.filter.SecurityActionFilter.authorizeRequest(SecurityActionFilter.java:210) ~[?:?]\n at org.elasticsearch.xpack.security.action.filter.SecurityActionFilter.lambda$applyInternal$3(SecurityActionFilter.java:186) ~[?:?]\n at org.elasticsearch.action.ActionListener$1.onResponse(ActionListener.java:59) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.lambda$authenticateAsync$2(AuthenticationService.java:212) ~[?:?]\n at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.lambda$lookForExistingAuthentication$4(AuthenticationService.java:246) ~[?:?]\n at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.lookForExistingAuthentication(AuthenticationService.java:257) ~[?:?]\n at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.authenticateAsync(AuthenticationService.java:210) ~[?:?]\n at org.elasticsearch.xpack.security.authc.AuthenticationService$Authenticator.access$000(AuthenticationService.java:159) ~[?:?]\n at org.elasticsearch.xpack.security.authc.AuthenticationService.authenticate(AuthenticationService.java:122) ~[?:?]\n at org.elasticsearch.xpack.security.action.filter.SecurityActionFilter.applyInternal(SecurityActionFilter.java:185) ~[?:?]\n at org.elasticsearch.xpack.security.action.filter.SecurityActionFilter.apply(SecurityActionFilter.java:145) ~[?:?]\n at org.elasticsearch.action.support.TransportAction$RequestFilterChain.proceed(TransportAction.java:168) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.action.support.TransportAction.execute(TransportAction.java:142) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.action.support.TransportAction.execute(TransportAction.java:84) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.client.node.NodeClient.executeLocally(NodeClient.java:83) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.client.node.NodeClient.doExecute(NodeClient.java:72) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.client.support.AbstractClient.execute(AbstractClient.java:408) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.action.ActionRequestBuilder.execute(ActionRequestBuilder.java:80) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.xpack.monitoring.rest.action.RestMonitoringBulkAction.lambda$doPrepareRequest$0(RestMonitoringBulkAction.java:77) ~[?:?]\n at org.elasticsearch.rest.BaseRestHandler.handleReques", "offset": 2907, "prospector.type": "log", @@ -201,6 +215,7 @@ "multiline" ], "log.level": "WARN", + "log.original": "[2018-07-03T11:48:02,552][WARN ][r.suppressed ] path: /_xpack/license, params: {}\norg.elasticsearch.discovery.MasterNotDiscoveredException: NodeDisconnectedException[[srvmulpvlsk250_md][180.39.9.91:9300][cluster:monitor/xpack/license/get] disconnected]\n at org.elasticsearch.action.support.master.TransportMasterNodeAction$AsyncSingleAction$4.onTimeout(TransportMasterNodeAction.java:209) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.cluster.ClusterStateObserver$ContextPreservingListener.onTimeout(ClusterStateObserver.java:311) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.cluster.ClusterStateObserver.waitForNextChange(ClusterStateObserver.java:139) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.cluster.ClusterStateObserver.waitForNextChange(ClusterStateObserver.java:111) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.action.support.master.TransportMasterNodeAction$AsyncSingleAction.retry(TransportMasterNodeAction.java:194) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.action.support.master.TransportMasterNodeAction$AsyncSingleAction.access$500(TransportMasterNodeAction.java:107) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.action.support.master.TransportMasterNodeAction$AsyncSingleAction$3.handleException(TransportMasterNodeAction.java:183) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.transport.TransportService$ContextRestoreResponseHandler.handleException(TransportService.java:1067) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.transport.TransportService$ContextRestoreResponseHandler.handleException(TransportService.java:1067) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.transport.TransportService$Adapter.lambda$onConnectionClosed$6(TransportService.java:893) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingRunnable.run(ThreadContext.java:569) [elasticsearch-5.6.3.jar:5.6.3]\n at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) [?:1.8.0_161]\n at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) [?:1.8.0_161]\n at java.lang.Thread.run(Thread.java:748) [?:1.8.0_161]\nCaused by: org.elasticsearch.transport.NodeDisconnectedException: [srvmulpvlsk250_md][180.39.9.91:9300][cluster:monitor/xpack/license/get] disconnected", "message": "path: /_xpack/license, params: {}\norg.elasticsearch.discovery.MasterNotDiscoveredException: NodeDisconnectedException[[srvmulpvlsk250_md][180.39.9.91:9300][cluster:monitor/xpack/license/get] disconnected]\n at org.elasticsearch.action.support.master.TransportMasterNodeAction$AsyncSingleAction$4.onTimeout(TransportMasterNodeAction.java:209) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.cluster.ClusterStateObserver$ContextPreservingListener.onTimeout(ClusterStateObserver.java:311) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.cluster.ClusterStateObserver.waitForNextChange(ClusterStateObserver.java:139) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.cluster.ClusterStateObserver.waitForNextChange(ClusterStateObserver.java:111) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.action.support.master.TransportMasterNodeAction$AsyncSingleAction.retry(TransportMasterNodeAction.java:194) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.action.support.master.TransportMasterNodeAction$AsyncSingleAction.access$500(TransportMasterNodeAction.java:107) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.action.support.master.TransportMasterNodeAction$AsyncSingleAction$3.handleException(TransportMasterNodeAction.java:183) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.transport.TransportService$ContextRestoreResponseHandler.handleException(TransportService.java:1067) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.transport.TransportService$ContextRestoreResponseHandler.handleException(TransportService.java:1067) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.transport.TransportService$Adapter.lambda$onConnectionClosed$6(TransportService.java:893) ~[elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingRunnable.run(ThreadContext.java:569) [elasticsearch-5.6.3.jar:5.6.3]\n at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) [?:1.8.0_161]\n at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) [?:1.8.0_161]\n at java.lang.Thread.run(Thread.java:748) [?:1.8.0_161]\nCaused by: org.elasticsearch.transport.NodeDisconnectedException: [srvmulpvlsk250_md][180.39.9.91:9300][cluster:monitor/xpack/license/get] disconnected", "offset": 7412, "prospector.type": "log", @@ -219,6 +234,7 @@ "multiline" ], "log.level": "WARN", + "log.original": "[2018-07-03T11:45:27,896][WARN ][o.e.m.j.JvmGcMonitorService] [srvmulpvlsk252_md] [gc][young][3449979][986594] duration [3.8s], collections [1]/[4.3s], total [3.8s]/[8.8h], memory [16.5gb]->[15.7gb]/[30.8gb], all_po\nols {[young] [1.2gb]->[24mb]/[1.4gb]}{[survivor] [191.3mb]->[191.3mb]/[191.3mb]}{[old] [15.1gb]->[15.5gb]/[29.1gb]}", "message": "duration [3.8s], collections [1]/[4.3s], total [3.8s]/[8.8h], memory [16.5gb]->[15.7gb]/[30.8gb], all_po\nols {[young] [1.2gb]->[24mb]/[1.4gb]}{[survivor] [191.3mb]->[191.3mb]/[191.3mb]}{[old] [15.1gb]->[15.5gb]/[29.1gb]}", "offset": 9873, "prospector.type": "log", @@ -233,6 +249,7 @@ "fileset.name": "server", "input.type": "log", "log.level": "WARN", + "log.original": "[2018-07-03T11:45:45,604][WARN ][o.e.m.j.JvmGcMonitorService] [srvmulpvlsk252_md] [gc][3449992] overhead, spent [1.6s] collecting in the last [1.8s]", "message": "overhead, spent [1.6s] collecting in the last [1.8s]", "offset": 10205, "prospector.type": "log", @@ -246,6 +263,7 @@ "fileset.name": "server", "input.type": "log", "log.level": "WARN", + "log.original": "[2018-07-03T11:48:02,541][WARN ][o.e.a.b.TransportShardBulkAction] [srvmulpvlsk252_md] [[pro_neocrmbigdata_paas-2018-27][0]] failed to perform indices:data/write/bulk[s] on replica [pro_neocrmbigdata_paas-2018-27][0], node[igrwSoPGSJ6u_5b8k26tgQ], [R], s[STARTED], a[id=DKK34YLHRMmJMkWg8jQH6w]", "message": "[[pro_neocrmbigdata_paas-2018-27][0]] failed to perform indices:data/write/bulk[s] on replica [pro_neocrmbigdata_paas-2018-27][0], node[igrwSoPGSJ6u_5b8k26tgQ], [R], s[STARTED], a[id=DKK34YLHRMmJMkWg8jQH6w]", "offset": 10354, "prospector.type": "log", @@ -262,6 +280,7 @@ "multiline" ], "log.level": "WARN", + "log.original": "[2018-07-03T20:10:07,376][WARN ][o.e.x.m.MonitoringService] [srvmulpvlsk252_md] monitoring execution failed\norg.elasticsearch.xpack.monitoring.exporter.ExportException: Exception when closing export bulk\n at org.elasticsearch.xpack.monitoring.exporter.ExportBulk$1$1.(ExportBulk.java:106) ~[?:?]\n at org.elasticsearch.xpack.monitoring.exporter.ExportBulk$1.onFailure(ExportBulk.java:104) ~[?:?]\n at org.elasticsearch.xpack.monitoring.exporter.ExportBulk$Compound$1.onResponse(ExportBulk.java:217) ~[?:?]\n at org.elasticsearch.xpack.monitoring.exporter.ExportBulk$Compound$1.onResponse(ExportBulk.java:211) ~[?:?]\n at org.elasticsearch.xpack.common.IteratingActionListener.onResponse(IteratingActionListener.java:108) ~[?:?]\n at org.elasticsearch.action.ActionListener$1.onResponse(ActionListener.java:59) [elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.xpack.monitoring.exporter.http.HttpExportBulk$1.onSuccess(HttpExportBulk.java:115) [x-pack-5.6.3.jar:5.6.3]\n at org.elasticsearch.client.RestClient$FailureTrackingResponseListener.onSuccess(RestClient.java:597) [elasticsearch-rest-client-5.6.3.jar:5.6.3]\n at org.elasticsearch.client.RestClient$1.completed(RestClient.java:352) [elasticsearch-rest-client-5.6.3.jar:5.6.3]\n at org.elasticsearch.client.RestClient$1.completed(RestClient.java:343) [elasticsearch-rest-client-5.6.3.jar:5.6.3]\n at org.apache.http.concurrent.BasicFuture.completed(BasicFuture.java:119) [httpcore-4.4.5.jar:4.4.5]\n at org.apache.http.impl.nio.client.DefaultClientExchangeHandlerImpl.responseCompleted(DefaultClientExchangeHandlerImpl.java:177) [httpasyncclient-4.1.2.jar:4.1.2]\n at org.apache.http.nio.protocol.HttpAsyncRequestExecutor.processResponse(HttpAsyncRequestExecutor.java:436) [httpcore-nio-4.4.5.jar:4.4.5]\n at org.apache.http.nio.protocol.HttpAsyncRequestExecutor.inputReady(HttpAsyncRequestExecutor.java:326) [httpcore-nio-4.4.5.jar:4.4.5]\n at org.apache.http.impl.nio.DefaultNHttpClientConnection.consumeInput(DefaultNHttpClientConnection.java:265) [httpcore-nio-4.4.5.jar:4.4.5]\n at org.apache.http.impl.nio.client.InternalIODispatch.onInputReady(InternalIODispatch.java:81) [httpasyncclient-4.1.2.jar:4.1.2]\n at org.apache.http.impl.nio.client.InternalIODispatch.onInputReady(InternalIODispatch.java:39) [httpasyncclient-4.1.2.jar:4.1.2]\n at org.apache.http.impl.nio.reactor.AbstractIODispatch.inputReady(AbstractIODispatch.java:114) [httpcore-nio-4.4.5.jar:4.4.5]\n at org.apache.http.impl.nio.reactor.BaseIOReactor.readable(BaseIOReactor.java:162) [httpcore-nio-4.4.5.jar:4.4.5]\n at org.apache.http.impl.nio.reactor.AbstractIOReactor.processEvent(AbstractIOReactor.java:337) [httpcore-nio-4.4.5.jar:4.4.5]\n at org.apache.http.impl.nio.reactor.AbstractIOReactor.processEvents(AbstractIOReactor.java:315) [httpcore-nio-4.4.5.jar:4.4.5]\n at org.apache.http.impl.nio.reactor.AbstractIOReactor.execute(AbstractIOReactor.java:276) [httpcore-nio-4.4.5.jar:4.4.5]\n at org.apache.http.impl.nio.reactor.BaseIOReactor.execute(BaseIOReactor.java:104) [httpcore-nio-4.4.5.jar:4.4.5]\n at org.apache.http.impl.nio.reactor.AbstractMultiworkerIOReactor$Worker.run(AbstractMultiworkerIOReactor.java:588) [httpcore-nio-4.4.5.jar:4.4.5]\n at java.lang.Thread.run(Thread.java:748) [?:1.8.0_161]\n", "message": "monitoring execution failed\norg.elasticsearch.xpack.monitoring.exporter.ExportException: Exception when closing export bulk\n at org.elasticsearch.xpack.monitoring.exporter.ExportBulk$1$1.(ExportBulk.java:106) ~[?:?]\n at org.elasticsearch.xpack.monitoring.exporter.ExportBulk$1.onFailure(ExportBulk.java:104) ~[?:?]\n at org.elasticsearch.xpack.monitoring.exporter.ExportBulk$Compound$1.onResponse(ExportBulk.java:217) ~[?:?]\n at org.elasticsearch.xpack.monitoring.exporter.ExportBulk$Compound$1.onResponse(ExportBulk.java:211) ~[?:?]\n at org.elasticsearch.xpack.common.IteratingActionListener.onResponse(IteratingActionListener.java:108) ~[?:?]\n at org.elasticsearch.action.ActionListener$1.onResponse(ActionListener.java:59) [elasticsearch-5.6.3.jar:5.6.3]\n at org.elasticsearch.xpack.monitoring.exporter.http.HttpExportBulk$1.onSuccess(HttpExportBulk.java:115) [x-pack-5.6.3.jar:5.6.3]\n at org.elasticsearch.client.RestClient$FailureTrackingResponseListener.onSuccess(RestClient.java:597) [elasticsearch-rest-client-5.6.3.jar:5.6.3]\n at org.elasticsearch.client.RestClient$1.completed(RestClient.java:352) [elasticsearch-rest-client-5.6.3.jar:5.6.3]\n at org.elasticsearch.client.RestClient$1.completed(RestClient.java:343) [elasticsearch-rest-client-5.6.3.jar:5.6.3]\n at org.apache.http.concurrent.BasicFuture.completed(BasicFuture.java:119) [httpcore-4.4.5.jar:4.4.5]\n at org.apache.http.impl.nio.client.DefaultClientExchangeHandlerImpl.responseCompleted(DefaultClientExchangeHandlerImpl.java:177) [httpasyncclient-4.1.2.jar:4.1.2]\n at org.apache.http.nio.protocol.HttpAsyncRequestExecutor.processResponse(HttpAsyncRequestExecutor.java:436) [httpcore-nio-4.4.5.jar:4.4.5]\n at org.apache.http.nio.protocol.HttpAsyncRequestExecutor.inputReady(HttpAsyncRequestExecutor.java:326) [httpcore-nio-4.4.5.jar:4.4.5]\n at org.apache.http.impl.nio.DefaultNHttpClientConnection.consumeInput(DefaultNHttpClientConnection.java:265) [httpcore-nio-4.4.5.jar:4.4.5]\n at org.apache.http.impl.nio.client.InternalIODispatch.onInputReady(InternalIODispatch.java:81) [httpasyncclient-4.1.2.jar:4.1.2]\n at org.apache.http.impl.nio.client.InternalIODispatch.onInputReady(InternalIODispatch.java:39) [httpasyncclient-4.1.2.jar:4.1.2]\n at org.apache.http.impl.nio.reactor.AbstractIODispatch.inputReady(AbstractIODispatch.java:114) [httpcore-nio-4.4.5.jar:4.4.5]\n at org.apache.http.impl.nio.reactor.BaseIOReactor.readable(BaseIOReactor.java:162) [httpcore-nio-4.4.5.jar:4.4.5]\n at org.apache.http.impl.nio.reactor.AbstractIOReactor.processEvent(AbstractIOReactor.java:337) [httpcore-nio-4.4.5.jar:4.4.5]\n at org.apache.http.impl.nio.reactor.AbstractIOReactor.processEvents(AbstractIOReactor.java:315) [httpcore-nio-4.4.5.jar:4.4.5]\n at org.apache.http.impl.nio.reactor.AbstractIOReactor.execute(AbstractIOReactor.java:276) [httpcore-nio-4.4.5.jar:4.4.5]\n at org.apache.http.impl.nio.reactor.BaseIOReactor.execute(BaseIOReactor.java:104) [httpcore-nio-4.4.5.jar:4.4.5]\n at org.apache.http.impl.nio.reactor.AbstractMultiworkerIOReactor$Worker.run(AbstractMultiworkerIOReactor.java:588) [httpcore-nio-4.4.5.jar:4.4.5]\n at java.lang.Thread.run(Thread.java:748) [?:1.8.0_161]\n", "offset": 10648, "prospector.type": "log", diff --git a/filebeat/module/elasticsearch/slowlog/test/test.log-expected.json b/filebeat/module/elasticsearch/slowlog/test/test.log-expected.json index c2a6ba28634..fe5ff9ecf08 100644 --- a/filebeat/module/elasticsearch/slowlog/test/test.log-expected.json +++ b/filebeat/module/elasticsearch/slowlog/test/test.log-expected.json @@ -17,6 +17,7 @@ "fileset.name": "slowlog", "input.type": "log", "log.level": "INFO", + "log.original": "[2018-06-29T10:06:14,933][INFO ][index.search.slowlog.query] [v_VJhjV] [metricbeat-6.3.0-2018.06.26][0] took[4.5ms], took_millis[4], total_hits[19435], types[], stats[], search_type[QUERY_THEN_FETCH], total_shards[1], source[{\"query\":{\"match_all\":{\"boost\":1.0}}}],", "message": "[2018-06-29T10:06:14,933][INFO ][index.search.slowlog.query] [v_VJhjV] [metricbeat-6.3.0-2018.06.26][0] took[4.5ms], took_millis[4], total_hits[19435], types[], stats[], search_type[QUERY_THEN_FETCH], total_shards[1], source[{\"query\":{\"match_all\":{\"boost\":1.0}}}],", "offset": 0, "prospector.type": "log", @@ -40,6 +41,7 @@ "fileset.name": "slowlog", "input.type": "log", "log.level": "INFO", + "log.original": "[2018-06-29T10:06:14,943][INFO ][index.search.slowlog.fetch] [v_VJhjV] [metricbeat-6.3.0-2018.06.26][0] took[10.8ms], took_millis[10], total_hits[19435], types[], stats[], search_type[QUERY_THEN_FETCH], total_shards[1], source[{\"query\":{\"match_all\":{\"boost\":1.0}}}],", "message": "[2018-06-29T10:06:14,943][INFO ][index.search.slowlog.fetch] [v_VJhjV] [metricbeat-6.3.0-2018.06.26][0] took[10.8ms], took_millis[10], total_hits[19435], types[], stats[], search_type[QUERY_THEN_FETCH], total_shards[1], source[{\"query\":{\"match_all\":{\"boost\":1.0}}}],", "offset": 265, "prospector.type": "log", @@ -63,6 +65,7 @@ "fileset.name": "slowlog", "input.type": "log", "log.level": "INFO", + "log.original": "[2018-06-29T09:01:01,821][INFO ][index.search.slowlog.query] [v_VJhjV] [metricbeat-6.3.0-2018.06.26][0] took[124.3ms], took_millis[124], total_hits[0], types[], stats[], search_type[QUERY_THEN_FETCH], total_shards[1], source[{\"size\":500,\"query\":{\"match_none\":{\"boost\":1.0}},\"version\":true,\"_source\":{\"includes\":[],\"excludes\":[]},\"stored_fields\":\"*\",\"docvalue_fields\":[\"@timestamp\",\"ceph.monitor_health.last_updated\",\"docker.container.created\",\"docker.healthcheck.event.end_date\",\"docker.healthcheck.event.start_date\",\"docker.image.created\",\"kubernetes.container.start_time\",\"kubernetes.event.metadata.timestamp.created\",\"kubernetes.node.start_time\",\"kubernetes.pod.start_time\",\"kubernetes.system.start_time\",\"mongodb.status.background_flushing.last_finished\",\"mongodb.status.local_time\",\"php_fpm.pool.start_time\",\"postgresql.activity.backend_start\",\"postgresql.activity.query_start\",\"postgresql.activity.state_change\",\"postgresql.activity.transaction_start\",\"postgresql.bgwriter.stats_reset\",\"postgresql.database.stats_reset\",\"system.process.cpu.start_time\"],\"script_fields\":{},\"sort\":[{\"@timestamp\":{\"order\":\"desc\",\"unmapped_type\":\"boolean\"}}],\"aggregations\":{\"2\":{\"date_histogram\":{\"field\":\"@timestamp\",\"time_zone\":\"Europe/Berlin\",\"interval\":\"30s\",\"offset\":0,\"order\":{\"_key\":\"asc\"},\"keyed\":false,\"min_doc_count\":1}}},\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fragment_size\":2147483647,\"fields\":{\"*\":{}}}}],", "message": "[2018-06-29T09:01:01,821][INFO ][index.search.slowlog.query] [v_VJhjV] [metricbeat-6.3.0-2018.06.26][0] took[124.3ms], took_millis[124], total_hits[0], types[], stats[], search_type[QUERY_THEN_FETCH], total_shards[1], source[{\"size\":500,\"query\":{\"match_none\":{\"boost\":1.0}},\"version\":true,\"_source\":{\"includes\":[],\"excludes\":[]},\"stored_fields\":\"*\",\"docvalue_fields\":[\"@timestamp\",\"ceph.monitor_health.last_updated\",\"docker.container.created\",\"docker.healthcheck.event.end_date\",\"docker.healthcheck.event.start_date\",\"docker.image.created\",\"kubernetes.container.start_time\",\"kubernetes.event.metadata.timestamp.created\",\"kubernetes.node.start_time\",\"kubernetes.pod.start_time\",\"kubernetes.system.start_time\",\"mongodb.status.background_flushing.last_finished\",\"mongodb.status.local_time\",\"php_fpm.pool.start_time\",\"postgresql.activity.backend_start\",\"postgresql.activity.query_start\",\"postgresql.activity.state_change\",\"postgresql.activity.transaction_start\",\"postgresql.bgwriter.stats_reset\",\"postgresql.database.stats_reset\",\"system.process.cpu.start_time\"],\"script_fields\":{},\"sort\":[{\"@timestamp\":{\"order\":\"desc\",\"unmapped_type\":\"boolean\"}}],\"aggregations\":{\"2\":{\"date_histogram\":{\"field\":\"@timestamp\",\"time_zone\":\"Europe/Berlin\",\"interval\":\"30s\",\"offset\":0,\"order\":{\"_key\":\"asc\"},\"keyed\":false,\"min_doc_count\":1}}},\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fragment_size\":2147483647,\"fields\":{\"*\":{}}}}],", "offset": 532, "prospector.type": "log", @@ -86,6 +89,7 @@ "fileset.name": "slowlog", "input.type": "log", "log.level": "INFO", + "log.original": "[2018-06-29T09:01:01,827][INFO ][index.search.slowlog.fetch] [v_VJhjV] [metricbeat-6.3.0-2018.06.26][0] took[7.2ms], took_millis[7], total_hits[0], types[], stats[], search_type[QUERY_THEN_FETCH], total_shards[1], source[{\"size\":500,\"query\":{\"match_none\":{\"boost\":1.0}},\"version\":true,\"_source\":{\"includes\":[],\"excludes\":[]},\"stored_fields\":\"*\",\"docvalue_fields\":[\"@timestamp\",\"ceph.monitor_health.last_updated\",\"docker.container.created\",\"docker.healthcheck.event.end_date\",\"docker.healthcheck.event.start_date\",\"docker.image.created\",\"kubernetes.container.start_time\",\"kubernetes.event.metadata.timestamp.created\",\"kubernetes.node.start_time\",\"kubernetes.pod.start_time\",\"kubernetes.system.start_time\",\"mongodb.status.background_flushing.last_finished\",\"mongodb.status.local_time\",\"php_fpm.pool.start_time\",\"postgresql.activity.backend_start\",\"postgresql.activity.query_start\",\"postgresql.activity.state_change\",\"postgresql.activity.transaction_start\",\"postgresql.bgwriter.stats_reset\",\"postgresql.database.stats_reset\",\"system.process.cpu.start_time\"],\"script_fields\":{},\"sort\":[{\"@timestamp\":{\"order\":\"desc\",\"unmapped_type\":\"boolean\"}}],\"aggregations\":{\"2\":{\"date_histogram\":{\"field\":\"@timestamp\",\"time_zone\":\"Europe/Berlin\",\"interval\":\"30s\",\"offset\":0,\"order\":{\"_key\":\"asc\"},\"keyed\":false,\"min_doc_count\":1}}},\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fragment_size\":2147483647,\"fields\":{\"*\":{}}}}],", "message": "[2018-06-29T09:01:01,827][INFO ][index.search.slowlog.fetch] [v_VJhjV] [metricbeat-6.3.0-2018.06.26][0] took[7.2ms], took_millis[7], total_hits[0], types[], stats[], search_type[QUERY_THEN_FETCH], total_shards[1], source[{\"size\":500,\"query\":{\"match_none\":{\"boost\":1.0}},\"version\":true,\"_source\":{\"includes\":[],\"excludes\":[]},\"stored_fields\":\"*\",\"docvalue_fields\":[\"@timestamp\",\"ceph.monitor_health.last_updated\",\"docker.container.created\",\"docker.healthcheck.event.end_date\",\"docker.healthcheck.event.start_date\",\"docker.image.created\",\"kubernetes.container.start_time\",\"kubernetes.event.metadata.timestamp.created\",\"kubernetes.node.start_time\",\"kubernetes.pod.start_time\",\"kubernetes.system.start_time\",\"mongodb.status.background_flushing.last_finished\",\"mongodb.status.local_time\",\"php_fpm.pool.start_time\",\"postgresql.activity.backend_start\",\"postgresql.activity.query_start\",\"postgresql.activity.state_change\",\"postgresql.activity.transaction_start\",\"postgresql.bgwriter.stats_reset\",\"postgresql.database.stats_reset\",\"system.process.cpu.start_time\"],\"script_fields\":{},\"sort\":[{\"@timestamp\":{\"order\":\"desc\",\"unmapped_type\":\"boolean\"}}],\"aggregations\":{\"2\":{\"date_histogram\":{\"field\":\"@timestamp\",\"time_zone\":\"Europe/Berlin\",\"interval\":\"30s\",\"offset\":0,\"order\":{\"_key\":\"asc\"},\"keyed\":false,\"min_doc_count\":1}}},\"highlight\":{\"pre_tags\":[\"@kibana-highlighted-field@\"],\"post_tags\":[\"@/kibana-highlighted-field@\"],\"fragment_size\":2147483647,\"fields\":{\"*\":{}}}}],", "offset": 1999, "prospector.type": "log", @@ -107,6 +111,7 @@ "fileset.name": "slowlog", "input.type": "log", "log.level": "INFO", + "log.original": "[2018-07-04T13:48:07,452][INFO ][index.indexing.slowlog.index] [v_VJhjV] [metricbeat-6.3.0-2018.07.04/VLKxBLvUSYuIMKzpacGjRg] took[1.4ms], took_millis[1], type[doc], id[KUyMZWQBk9jw4gtg2y5-], routing[], source[{\"@timestamp\":\"2018-07-04T13:47:50.747Z\",\"system\":{\"process\":{\"ppid\":34526,\"state\":\"running\",\"cpu\":{\"total\":{\"value\":734879,\"pct\":0.0173,\"norm\":{\"pct\":0.0043}},\"start_time\":\"2018-07-04T06:56:34.863Z\"},\"pgid\":34526,\"cmdline\":\"/Applications/Firefox.app/Contents/MacOS/plugin-container.app/Contents/MacOS/plugin-container -childID 1 -isForBrowser -prefsLen 22119 -schedulerPrefs 0001,2 -greomni /Applications/Firefox.app/Contents/Resources/omni.ja -appomni /Applications/Firefox.app/Contents/Resources/browser/omni.ja -appdir /Applications/Firefox.app/Contents/Resources/browser -profile /Users/rado/Library/Application Support/Firefox/Profiles/pt6eoq1j.default-1484133908360 34526 gecko-crash-server-pipe.34526 org.mozilla.machname.231926932 tab\",\"name\":\"plugin-containe\",\"memory\":{\"size\":7489249280,\"rss\":{\"bytes\":567619584,\"pct\":0.033},\"share\":0},\"pid\":34528,\"username\":\"rado\"}},\"metricset\":{\"name\":\"process\",\"module\":\"system\",\"rtt\":43856},\"beat\":{\"hostname\":\"Rados-MacBook-Pro.local\",\"version\":\"6.3.0\",\"name\":\"Rados-MacBook-Pro.local\"},\"host\":{\"name\":\"Rados-MacBook-Pro.local\"}}]", "message": "[2018-07-04T13:48:07,452][INFO ][index.indexing.slowlog.index] [v_VJhjV] [metricbeat-6.3.0-2018.07.04/VLKxBLvUSYuIMKzpacGjRg] took[1.4ms], took_millis[1], type[doc], id[KUyMZWQBk9jw4gtg2y5-], routing[], source[{\"@timestamp\":\"2018-07-04T13:47:50.747Z\",\"system\":{\"process\":{\"ppid\":34526,\"state\":\"running\",\"cpu\":{\"total\":{\"value\":734879,\"pct\":0.0173,\"norm\":{\"pct\":0.0043}},\"start_time\":\"2018-07-04T06:56:34.863Z\"},\"pgid\":34526,\"cmdline\":\"/Applications/Firefox.app/Contents/MacOS/plugin-container.app/Contents/MacOS/plugin-container -childID 1 -isForBrowser -prefsLen 22119 -schedulerPrefs 0001,2 -greomni /Applications/Firefox.app/Contents/Resources/omni.ja -appomni /Applications/Firefox.app/Contents/Resources/browser/omni.ja -appdir /Applications/Firefox.app/Contents/Resources/browser -profile /Users/rado/Library/Application Support/Firefox/Profiles/pt6eoq1j.default-1484133908360 34526 gecko-crash-server-pipe.34526 org.mozilla.machname.231926932 tab\",\"name\":\"plugin-containe\",\"memory\":{\"size\":7489249280,\"rss\":{\"bytes\":567619584,\"pct\":0.033},\"share\":0},\"pid\":34528,\"username\":\"rado\"}},\"metricset\":{\"name\":\"process\",\"module\":\"system\",\"rtt\":43856},\"beat\":{\"hostname\":\"Rados-MacBook-Pro.local\",\"version\":\"6.3.0\",\"name\":\"Rados-MacBook-Pro.local\"},\"host\":{\"name\":\"Rados-MacBook-Pro.local\"}}]", "offset": 3462, "prospector.type": "log", @@ -131,6 +136,7 @@ "multiline" ], "log.level": "INFO", + "log.original": "[2018-07-04T21:51:30,411][INFO ][index.indexing.slowlog.index] [v_VJhjV] [metricbeat-6.3.0-2018.07.04/VLKxBLvUSYuIMKzpacGjRg] took[1.7ms], took_millis[1], type[doc], id[s01HZ2QBk9jw4gtgaFtn], routing[], source[\n{\n \"@timestamp\":\"2018-07-04T21:27:30.730Z\",\n \"metricset\":{\n \"name\":\"network\",\n \"module\":\"system\",\n \"rtt\":7264},\n \"system\":{\n \"network\":{\n \"name\":\"lo0\",\n \"in\":{\n \"errors\":0,\n \"dropped\":0,\n \"bytes\":77666873,\n \"packets\":244595},\n \"out\":{\n \"packets\":244595,\n \"bytes\":77666873,\n \"errors\":0,\n \"dropped\":0\n }\n }\n },\n \"beat\":{\n \"name\":\"Rados-MacBook-Pro.local\",\n \"hostname\":\"Rados-MacBook-Pro.local\",\n \"version\":\"6.3.0\"\n },\n \"host\":{\n \"name\":\"Rados-MacBook-Pro.local\"\n }\n }]", "message": "[2018-07-04T21:51:30,411][INFO ][index.indexing.slowlog.index] [v_VJhjV] [metricbeat-6.3.0-2018.07.04/VLKxBLvUSYuIMKzpacGjRg] took[1.7ms], took_millis[1], type[doc], id[s01HZ2QBk9jw4gtgaFtn], routing[], source[\n{\n \"@timestamp\":\"2018-07-04T21:27:30.730Z\",\n \"metricset\":{\n \"name\":\"network\",\n \"module\":\"system\",\n \"rtt\":7264},\n \"system\":{\n \"network\":{\n \"name\":\"lo0\",\n \"in\":{\n \"errors\":0,\n \"dropped\":0,\n \"bytes\":77666873,\n \"packets\":244595},\n \"out\":{\n \"packets\":244595,\n \"bytes\":77666873,\n \"errors\":0,\n \"dropped\":0\n }\n }\n },\n \"beat\":{\n \"name\":\"Rados-MacBook-Pro.local\",\n \"hostname\":\"Rados-MacBook-Pro.local\",\n \"version\":\"6.3.0\"\n },\n \"host\":{\n \"name\":\"Rados-MacBook-Pro.local\"\n }\n }]", "offset": 4753, "prospector.type": "log", diff --git a/filebeat/module/haproxy/log/test/haproxy.log-expected.json b/filebeat/module/haproxy/log/test/haproxy.log-expected.json index 990ec9ae854..4a0bc0add19 100644 --- a/filebeat/module/haproxy/log/test/haproxy.log-expected.json +++ b/filebeat/module/haproxy/log/test/haproxy.log-expected.json @@ -37,6 +37,7 @@ "haproxy.time_queue": 0, "haproxy.time_server_response": 0, "input.type": "log", + "log.original": "Jul 30 09:03:52 localhost haproxy[32450]: 1.2.3.4:38862 [30/Jul/2018:09:03:52.726] incoming~ docs_microservice/docs 0/0/1/0/2 304 168 - - ---- 6/6/0/0/0 0/0 {docs.example.internal||} {|||} \"GET /component---src-pages-index-js-4b15624544f97cf0bb8f.js HTTP/1.1\"", "message": "Jul 30 09:03:52 localhost haproxy[32450]: 1.2.3.4:38862 [30/Jul/2018:09:03:52.726] incoming~ docs_microservice/docs 0/0/1/0/2 304 168 - - ---- 6/6/0/0/0 0/0 {docs.example.internal||} {|||} \"GET /component---src-pages-index-js-4b15624544f97cf0bb8f.js HTTP/1.1\"", "offset": 0, "prospector.type": "log" diff --git a/filebeat/module/icinga/_meta/config.reference.yml b/filebeat/module/icinga/_meta/config.reference.yml index bbddd5bdbc6..7135d35978e 100644 --- a/filebeat/module/icinga/_meta/config.reference.yml +++ b/filebeat/module/icinga/_meta/config.reference.yml @@ -10,6 +10,8 @@ # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true # Debug logs #debug: @@ -22,6 +24,8 @@ # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true # Startup logs #startup: @@ -34,3 +38,5 @@ # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true diff --git a/filebeat/module/icinga/debug/test/test.log-expected.json b/filebeat/module/icinga/debug/test/test.log-expected.json index 2a8ec5dbb7d..68f48973263 100644 --- a/filebeat/module/icinga/debug/test/test.log-expected.json +++ b/filebeat/module/icinga/debug/test/test.log-expected.json @@ -7,6 +7,7 @@ "icinga.debug.message": "Add to metric list:'icinga2.demo.services.procs.procs.perfdata.procs.warn 250 1491306189'.", "icinga.debug.severity": "debug", "input.type": "log", + "log.original": "[2017-04-04 13:43:09 +0200] debug/GraphiteWriter: Add to metric list:'icinga2.demo.services.procs.procs.perfdata.procs.warn 250 1491306189'.", "offset": 0, "prospector.type": "log" }, @@ -18,6 +19,7 @@ "icinga.debug.message": "Query: UPDATE icinga_servicestatus SET acknowledgement_type = '0', active_checks_enabled = '1', check_command = 'mysql_health', check_source = 'demo', check_type = '0', current_check_attempt = '1', current_notification_number = '180', current_state = '2', endpoint_object_id = 242, event_handler = '', event_handler_enabled = '1', execution_time = '0.355594', flap_detection_enabled = '0', has_been_checked = '1', instance_id = 1, is_flapping = '0', is_reachable = '1', last_check = FROM_UNIXTIME(1491306189), last_hard_state = '2', last_hard_state_change = FROM_UNIXTIME(1491290599), last_notification = FROM_UNIXTIME(1491304989), last_state_change = FROM_UNIXTIME(1491290599), last_time_critical = FROM_UNIXTIME(1491306189), last_time_unknown = FROM_UNIXTIME(1491290589), latency = '0.001466', long_output = '', max_check_attempts = '5', next_check = FROM_UNIXTIME(1491306198), next_notification = FROM_UNIXTIME(1491306789), normal_check_interval = '0.166667', notifications_enabled = '1', original_attributes = 'null', output = 'CRITICAL - cannot connect to information_schema. Access denied for user \\'test1\\'@\\'blerims-mbp.int.netways.de\\' (using password: YES)', passive_checks_enabled = '1', percent_state_change = '0', perfdata = '', problem_has_been_acknowledged = '0', process_performance_data = '1', retry_check_interval = '0.166667', scheduled_downtime_depth = '0', service_object_id = 333, should_be_scheduled = '1', state_type = '1', status_update_time = FROM_UNIXTIME(1491306189) WHERE service_object_id = 333", "icinga.debug.severity": "debug", "input.type": "log", + "log.original": "[2017-04-04 13:43:09 +0200] debug/IdoMysqlConnection: Query: UPDATE icinga_servicestatus SET acknowledgement_type = '0', active_checks_enabled = '1', check_command = 'mysql_health', check_source = 'demo', check_type = '0', current_check_attempt = '1', current_notification_number = '180', current_state = '2', endpoint_object_id = 242, event_handler = '', event_handler_enabled = '1', execution_time = '0.355594', flap_detection_enabled = '0', has_been_checked = '1', instance_id = 1, is_flapping = '0', is_reachable = '1', last_check = FROM_UNIXTIME(1491306189), last_hard_state = '2', last_hard_state_change = FROM_UNIXTIME(1491290599), last_notification = FROM_UNIXTIME(1491304989), last_state_change = FROM_UNIXTIME(1491290599), last_time_critical = FROM_UNIXTIME(1491306189), last_time_unknown = FROM_UNIXTIME(1491290589), latency = '0.001466', long_output = '', max_check_attempts = '5', next_check = FROM_UNIXTIME(1491306198), next_notification = FROM_UNIXTIME(1491306789), normal_check_interval = '0.166667', notifications_enabled = '1', original_attributes = 'null', output = 'CRITICAL - cannot connect to information_schema. Access denied for user \\'test1\\'@\\'blerims-mbp.int.netways.de\\' (using password: YES)', passive_checks_enabled = '1', percent_state_change = '0', perfdata = '', problem_has_been_acknowledged = '0', process_performance_data = '1', retry_check_interval = '0.166667', scheduled_downtime_depth = '0', service_object_id = 333, should_be_scheduled = '1', state_type = '1', status_update_time = FROM_UNIXTIME(1491306189) WHERE service_object_id = 333", "offset": 141, "prospector.type": "log" }, @@ -29,6 +31,7 @@ "icinga.debug.message": "Running command '/usr/lib/nagios/plugins/check_ping' '-H' 'mysql.icinga.com' '-c' '5000,100%' '-w' '3000,80%': PID 8288", "icinga.debug.severity": "notice", "input.type": "log", + "log.original": "[2017-04-04 13:43:11 +0200] notice/Process: Running command '/usr/lib/nagios/plugins/check_ping' '-H' 'mysql.icinga.com' '-c' '5000,100%' '-w' '3000,80%': PID 8288", "offset": 1763, "prospector.type": "log" } diff --git a/filebeat/module/icinga/main/test/test.log-expected.json b/filebeat/module/icinga/main/test/test.log-expected.json index 59d4822ce5d..ecc24a85631 100644 --- a/filebeat/module/icinga/main/test/test.log-expected.json +++ b/filebeat/module/icinga/main/test/test.log-expected.json @@ -7,6 +7,7 @@ "icinga.main.message": "Sending 'Recovery' notification 'demo!load!mail-icingaadmin for user 'on-call'", "icinga.main.severity": "information", "input.type": "log", + "log.original": "[2017-04-04 11:16:34 +0200] information/Notification: Sending 'Recovery' notification 'demo!load!mail-icingaadmin for user 'on-call'", "offset": 0, "prospector.type": "log" }, @@ -21,6 +22,7 @@ "log.flags": [ "multiline" ], + "log.original": "[2017-04-04 11:16:34 +0200] warning/PluginNotificationTask: Notification command for object 'demo!load' (PID: 19401, arguments: '/etc/icinga2/scripts/mail-service-notification.sh') terminated with exit code 127, output: /etc/icinga2/scripts/mail-service-notification.sh: 20: /etc/icinga2/scripts/mail-service-notification.sh: mail: not found\n/usr/bin/printf: write error: Broken pipe\n", "offset": 133, "prospector.type": "log" }, @@ -32,6 +34,7 @@ "icinga.main.message": "Query queue items: 0, query rate: 5.38333/s (323/min 1610/5min 4778/15min);", "icinga.main.severity": "information", "input.type": "log", + "log.original": "[2017-04-04 11:16:48 +0200] information/IdoMysqlConnection: Query queue items: 0, query rate: 5.38333/s (323/min 1610/5min 4778/15min);", "offset": 518, "prospector.type": "log" } diff --git a/filebeat/module/icinga/startup/test/test.log-expected.json b/filebeat/module/icinga/startup/test/test.log-expected.json index 2f8cd6198c4..b385a6738cf 100644 --- a/filebeat/module/icinga/startup/test/test.log-expected.json +++ b/filebeat/module/icinga/startup/test/test.log-expected.json @@ -7,6 +7,7 @@ "icinga.startup.message": "Icinga application loader (version: r2.6.3-1)", "icinga.startup.severity": "information", "input.type": "log", + "log.original": "information/cli: Icinga application loader (version: r2.6.3-1)", "offset": 0, "prospector.type": "log" }, @@ -18,6 +19,7 @@ "icinga.startup.message": "Loading configuration file(s).", "icinga.startup.severity": "information", "input.type": "log", + "log.original": "information/cli: Loading configuration file(s).", "offset": 63, "prospector.type": "log" } diff --git a/filebeat/module/iis/_meta/config.reference.yml b/filebeat/module/iis/_meta/config.reference.yml index aebe3e38b09..042926ea067 100644 --- a/filebeat/module/iis/_meta/config.reference.yml +++ b/filebeat/module/iis/_meta/config.reference.yml @@ -10,6 +10,8 @@ # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true # Error logs #error: @@ -22,3 +24,5 @@ # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true diff --git a/filebeat/module/iis/access/test/test.log-expected.json b/filebeat/module/iis/access/test/test.log-expected.json index 2ef4c983d07..42b08568371 100644 --- a/filebeat/module/iis/access/test/test.log-expected.json +++ b/filebeat/module/iis/access/test/test.log-expected.json @@ -30,6 +30,7 @@ "iis.access.user_name": "-", "iis.access.win32_status": "0", "input.type": "log", + "log.original": "2018-01-01 08:09:10 127.0.0.1 GET / q=100 80 - 85.181.35.98 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+rv:57.0)+Gecko/20100101+Firefox/57.0 - 200 0 0 123", "offset": 257, "prospector.type": "log" }, @@ -61,6 +62,7 @@ "iis.access.user_name": "-", "iis.access.win32_status": "0", "input.type": "log", + "log.original": "2018-01-01 09:10:11 W3SVC1 GET / - 80 - 127.0.0.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+rv:57.0)+Gecko/20100101+Firefox/57.0 - - example.com 200 0 0 123 456 789", "offset": 709, "prospector.type": "log" }, @@ -102,6 +104,7 @@ "iis.access.user_name": "-", "iis.access.win32_status": "0", "input.type": "log", + "log.original": "2018-01-01 10:11:12 W3SVC1 MACHINE-NAME 127.0.0.1 GET / - 80 - 85.181.35.98 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+rv:57.0)+Gecko/20100101+Firefox/57.0 - - example.com 200 0 0 123 456 789", "offset": 1204, "prospector.type": "log" } diff --git a/filebeat/module/iis/error/test/test.log-expected.json b/filebeat/module/iis/error/test/test.log-expected.json index ad14babac55..aaea72919f8 100644 --- a/filebeat/module/iis/error/test/test.log-expected.json +++ b/filebeat/module/iis/error/test/test.log-expected.json @@ -14,6 +14,7 @@ "iis.error.server_port": "80", "iis.error.url": "/qos/1kbfile.txt", "input.type": "log", + "log.original": "2018-01-01 08:09:10 172.31.77.6 2094 172.31.77.6 80 HTTP/1.1 GET /qos/1kbfile.txt 503 - ConnLimit -", "offset": 186, "prospector.type": "log" }, @@ -39,6 +40,7 @@ "iis.error.server_port": "80", "iis.error.url": "/ThisIsMyUrl.htm", "input.type": "log", + "log.original": "2018-01-01 09:10:11 85.181.35.98 2780 127.0.0.1 80 HTTP/1.1 GET /ThisIsMyUrl.htm 400 - Hostname -", "offset": 286, "prospector.type": "log" }, @@ -64,6 +66,7 @@ "iis.error.server_port": "80", "iis.error.url": "/", "input.type": "log", + "log.original": "2018-01-01 10:11:12 85.181.35.98 2894 127.0.0.1 80 HTTP/2.0 GET / 505 - Version_N/S -", "offset": 384, "prospector.type": "log" }, @@ -85,6 +88,7 @@ "iis.error.server_ip": "127.0.0.1", "iis.error.server_port": "80", "input.type": "log", + "log.original": "2018-01-01 11:12:13 85.181.35.98 64388 127.0.0.1 80 - - - - - Timer_MinBytesPerSecond -", "offset": 470, "prospector.type": "log" } diff --git a/filebeat/module/kafka/log/test/controller.log-expected.json b/filebeat/module/kafka/log/test/controller.log-expected.json index 698fde1e230..57829118ee6 100644 --- a/filebeat/module/kafka/log/test/controller.log-expected.json +++ b/filebeat/module/kafka/log/test/controller.log-expected.json @@ -8,6 +8,7 @@ "kafka.log.component": "controller-event-thread", "kafka.log.level": "INFO", "kafka.log.message": "Starting", + "log.original": "[2017-08-04 10:48:21,048] INFO [controller-event-thread]: Starting (kafka.controller.ControllerEventManager$ControllerEventThread)", "message": "[2017-08-04 10:48:21,048] INFO [controller-event-thread]: Starting (kafka.controller.ControllerEventManager$ControllerEventThread)", "offset": 0, "prospector.type": "log" @@ -21,6 +22,7 @@ "kafka.log.component": "Controller 0", "kafka.log.level": "INFO", "kafka.log.message": "0 successfully elected as the controller", + "log.original": "[2017-08-04 10:48:21,063] INFO [Controller 0]: 0 successfully elected as the controller (kafka.controller.KafkaController)", "message": "[2017-08-04 10:48:21,063] INFO [Controller 0]: 0 successfully elected as the controller (kafka.controller.KafkaController)", "offset": 131, "prospector.type": "log" @@ -34,6 +36,7 @@ "kafka.log.component": "Controller 0", "kafka.log.level": "INFO", "kafka.log.message": "Broker 0 starting become controller state transition", + "log.original": "[2017-08-04 10:48:21,064] INFO [Controller 0]: Broker 0 starting become controller state transition (kafka.controller.KafkaController)", "message": "[2017-08-04 10:48:21,064] INFO [Controller 0]: Broker 0 starting become controller state transition (kafka.controller.KafkaController)", "offset": 254, "prospector.type": "log" @@ -47,6 +50,7 @@ "kafka.log.component": "Controller 0", "kafka.log.level": "INFO", "kafka.log.message": "Controller 0 incremented epoch to 1", + "log.original": "[2017-08-04 10:48:21,082] INFO [Controller 0]: Controller 0 incremented epoch to 1 (kafka.controller.KafkaController)", "message": "[2017-08-04 10:48:21,082] INFO [Controller 0]: Controller 0 incremented epoch to 1 (kafka.controller.KafkaController)", "offset": 389, "prospector.type": "log" @@ -60,6 +64,7 @@ "kafka.log.component": "Controller 0", "kafka.log.level": "DEBUG", "kafka.log.message": "Registering IsrChangeNotificationListener", + "log.original": "[2017-08-04 10:48:21,085] DEBUG [Controller 0]: Registering IsrChangeNotificationListener (kafka.controller.KafkaController)", "message": "[2017-08-04 10:48:21,085] DEBUG [Controller 0]: Registering IsrChangeNotificationListener (kafka.controller.KafkaController)", "offset": 507, "prospector.type": "log" @@ -73,6 +78,7 @@ "kafka.log.component": "Replica state machine on controller 0", "kafka.log.level": "INFO", "kafka.log.message": "Started replica state machine with initial state -> Map()", + "log.original": "[2017-08-04 10:48:21,154] INFO [Replica state machine on controller 0]: Started replica state machine with initial state -> Map() (kafka.controller.ReplicaStateMachine)", "message": "[2017-08-04 10:48:21,154] INFO [Replica state machine on controller 0]: Started replica state machine with initial state -> Map() (kafka.controller.ReplicaStateMachine)", "offset": 632, "prospector.type": "log" @@ -86,6 +92,7 @@ "kafka.log.component": "Partition state machine on Controller 0", "kafka.log.level": "INFO", "kafka.log.message": "Started partition state machine with initial state -> Map()", + "log.original": "[2017-08-04 10:48:21,156] INFO [Partition state machine on Controller 0]: Started partition state machine with initial state -> Map() (kafka.controller.PartitionStateMachine)", "message": "[2017-08-04 10:48:21,156] INFO [Partition state machine on Controller 0]: Started partition state machine with initial state -> Map() (kafka.controller.PartitionStateMachine)", "offset": 801, "prospector.type": "log" @@ -99,6 +106,7 @@ "kafka.log.component": "Controller 0", "kafka.log.level": "INFO", "kafka.log.message": "Broker 0 is ready to serve as the new controller with epoch 1", + "log.original": "[2017-08-04 10:48:21,157] INFO [Controller 0]: Broker 0 is ready to serve as the new controller with epoch 1 (kafka.controller.KafkaController)", "message": "[2017-08-04 10:48:21,157] INFO [Controller 0]: Broker 0 is ready to serve as the new controller with epoch 1 (kafka.controller.KafkaController)", "offset": 976, "prospector.type": "log" @@ -112,6 +120,7 @@ "kafka.log.component": "Partition state machine on Controller 0", "kafka.log.level": "INFO", "kafka.log.message": "Invoking state change to OnlinePartition for partitions ", + "log.original": "[2017-08-04 10:48:21,165] INFO [Partition state machine on Controller 0]: Invoking state change to OnlinePartition for partitions (kafka.controller.PartitionStateMachine)", "message": "[2017-08-04 10:48:21,165] INFO [Partition state machine on Controller 0]: Invoking state change to OnlinePartition for partitions (kafka.controller.PartitionStateMachine)", "offset": 1120, "prospector.type": "log" @@ -125,6 +134,7 @@ "kafka.log.component": "Controller 0", "kafka.log.level": "DEBUG", "kafka.log.message": "Live brokers: ", + "log.original": "[2017-08-04 11:44:22,588] DEBUG [Controller 0]: Live brokers: (kafka.controller.KafkaController)", "message": "[2017-08-04 11:44:22,588] DEBUG [Controller 0]: Live brokers: (kafka.controller.KafkaController)", "offset": 1292, "prospector.type": "log" @@ -138,6 +148,7 @@ "kafka.log.component": "controller-event-thread", "kafka.log.level": "INFO", "kafka.log.message": "Shutting down", + "log.original": "[2017-08-04 11:44:25,094] INFO [controller-event-thread]: Shutting down (kafka.controller.ControllerEventManager$ControllerEventThread)", "message": "[2017-08-04 11:44:25,094] INFO [controller-event-thread]: Shutting down (kafka.controller.ControllerEventManager$ControllerEventThread)", "offset": 1390, "prospector.type": "log" @@ -151,6 +162,7 @@ "kafka.log.component": "controller-event-thread", "kafka.log.level": "INFO", "kafka.log.message": "Stopped", + "log.original": "[2017-08-04 11:44:25,095] INFO [controller-event-thread]: Stopped (kafka.controller.ControllerEventManager$ControllerEventThread)", "message": "[2017-08-04 11:44:25,095] INFO [controller-event-thread]: Stopped (kafka.controller.ControllerEventManager$ControllerEventThread)", "offset": 1526, "prospector.type": "log" @@ -164,6 +176,7 @@ "kafka.log.component": "controller-event-thread", "kafka.log.level": "INFO", "kafka.log.message": "Shutdown completed", + "log.original": "[2017-08-04 11:44:25,097] INFO [controller-event-thread]: Shutdown completed (kafka.controller.ControllerEventManager$ControllerEventThread)", "message": "[2017-08-04 11:44:25,097] INFO [controller-event-thread]: Shutdown completed (kafka.controller.ControllerEventManager$ControllerEventThread)", "offset": 1656, "prospector.type": "log" @@ -177,6 +190,7 @@ "kafka.log.component": "Controller 0", "kafka.log.level": "DEBUG", "kafka.log.message": "Controller resigning, broker id 0", + "log.original": "[2017-08-04 11:44:25,099] DEBUG [Controller 0]: Controller resigning, broker id 0 (kafka.controller.KafkaController)", "message": "[2017-08-04 11:44:25,099] DEBUG [Controller 0]: Controller resigning, broker id 0 (kafka.controller.KafkaController)", "offset": 1797, "prospector.type": "log" @@ -190,6 +204,7 @@ "kafka.log.component": "Controller 0", "kafka.log.level": "DEBUG", "kafka.log.message": "De-registering IsrChangeNotificationListener", + "log.original": "[2017-08-04 11:44:25,100] DEBUG [Controller 0]: De-registering IsrChangeNotificationListener (kafka.controller.KafkaController)", "message": "[2017-08-04 11:44:25,100] DEBUG [Controller 0]: De-registering IsrChangeNotificationListener (kafka.controller.KafkaController)", "offset": 1914, "prospector.type": "log" @@ -203,6 +218,7 @@ "kafka.log.component": "Partition state machine on Controller 0", "kafka.log.level": "INFO", "kafka.log.message": "Stopped partition state machine", + "log.original": "[2017-08-04 11:44:25,105] INFO [Partition state machine on Controller 0]: Stopped partition state machine (kafka.controller.PartitionStateMachine)", "message": "[2017-08-04 11:44:25,105] INFO [Partition state machine on Controller 0]: Stopped partition state machine (kafka.controller.PartitionStateMachine)", "offset": 2042, "prospector.type": "log" @@ -216,6 +232,7 @@ "kafka.log.component": "Replica state machine on controller 0", "kafka.log.level": "INFO", "kafka.log.message": "Stopped replica state machine", + "log.original": "[2017-08-04 11:44:25,111] INFO [Replica state machine on controller 0]: Stopped replica state machine (kafka.controller.ReplicaStateMachine)", "message": "[2017-08-04 11:44:25,111] INFO [Replica state machine on controller 0]: Stopped replica state machine (kafka.controller.ReplicaStateMachine)", "offset": 2189, "prospector.type": "log" @@ -229,6 +246,7 @@ "kafka.log.component": "Controller-0-to-broker-0-send-thread", "kafka.log.level": "INFO", "kafka.log.message": "Shutting down", + "log.original": "[2017-08-04 11:44:25,112] INFO [Controller-0-to-broker-0-send-thread]: Shutting down (kafka.controller.RequestSendThread)", "message": "[2017-08-04 11:44:25,112] INFO [Controller-0-to-broker-0-send-thread]: Shutting down (kafka.controller.RequestSendThread)", "offset": 2330, "prospector.type": "log" @@ -242,6 +260,7 @@ "kafka.log.component": "Controller-0-to-broker-0-send-thread", "kafka.log.level": "INFO", "kafka.log.message": "Stopped", + "log.original": "[2017-08-04 11:44:25,112] INFO [Controller-0-to-broker-0-send-thread]: Stopped (kafka.controller.RequestSendThread)", "message": "[2017-08-04 11:44:25,112] INFO [Controller-0-to-broker-0-send-thread]: Stopped (kafka.controller.RequestSendThread)", "offset": 2452, "prospector.type": "log" @@ -255,6 +274,7 @@ "kafka.log.component": "Controller-0-to-broker-0-send-thread", "kafka.log.level": "INFO", "kafka.log.message": "Shutdown completed", + "log.original": "[2017-08-04 11:44:25,113] INFO [Controller-0-to-broker-0-send-thread]: Shutdown completed (kafka.controller.RequestSendThread)", "message": "[2017-08-04 11:44:25,113] INFO [Controller-0-to-broker-0-send-thread]: Shutdown completed (kafka.controller.RequestSendThread)", "offset": 2568, "prospector.type": "log" diff --git a/filebeat/module/kafka/log/test/server.log-expected.json b/filebeat/module/kafka/log/test/server.log-expected.json index 15b904ad343..9637092e141 100644 --- a/filebeat/module/kafka/log/test/server.log-expected.json +++ b/filebeat/module/kafka/log/test/server.log-expected.json @@ -8,6 +8,7 @@ "kafka.log.component": "unknown", "kafka.log.level": "INFO", "kafka.log.message": "starting", + "log.original": "[2017-08-04 10:48:20,377] INFO starting (kafka.server.KafkaServer)", "message": "[2017-08-04 10:48:20,377] INFO starting (kafka.server.KafkaServer)", "offset": 0, "prospector.type": "log" @@ -21,6 +22,7 @@ "kafka.log.component": "unknown", "kafka.log.level": "INFO", "kafka.log.message": "Connecting to zookeeper on localhost:2181", + "log.original": "[2017-08-04 10:48:20,379] INFO Connecting to zookeeper on localhost:2181 (kafka.server.KafkaServer)", "message": "[2017-08-04 10:48:20,379] INFO Connecting to zookeeper on localhost:2181 (kafka.server.KafkaServer)", "offset": 67, "prospector.type": "log" @@ -34,6 +36,7 @@ "kafka.log.component": "unknown", "kafka.log.level": "INFO", "kafka.log.message": "Client environment:java.io.tmpdir=/tmp", + "log.original": "[2017-08-04 10:48:20,400] INFO Client environment:java.io.tmpdir=/tmp (org.apache.zookeeper.ZooKeeper)", "message": "[2017-08-04 10:48:20,400] INFO Client environment:java.io.tmpdir=/tmp (org.apache.zookeeper.ZooKeeper)", "offset": 167, "prospector.type": "log" @@ -47,6 +50,7 @@ "kafka.log.component": "unknown", "kafka.log.level": "INFO", "kafka.log.message": "Client environment:java.compiler=", + "log.original": "[2017-08-04 10:48:20,400] INFO Client environment:java.compiler= (org.apache.zookeeper.ZooKeeper)", "message": "[2017-08-04 10:48:20,400] INFO Client environment:java.compiler= (org.apache.zookeeper.ZooKeeper)", "offset": 270, "prospector.type": "log" @@ -60,6 +64,7 @@ "kafka.log.component": "unknown", "kafka.log.level": "INFO", "kafka.log.message": "Initiating client connection, connectString=localhost:2181 sessionTimeout=6000 watcher=org.I0Itec.zkclient.ZkClient@5ffead27", + "log.original": "[2017-08-04 10:48:20,401] INFO Initiating client connection, connectString=localhost:2181 sessionTimeout=6000 watcher=org.I0Itec.zkclient.ZkClient@5ffead27 (org.apache.zookeeper.ZooKeeper)", "message": "[2017-08-04 10:48:20,401] INFO Initiating client connection, connectString=localhost:2181 sessionTimeout=6000 watcher=org.I0Itec.zkclient.ZkClient@5ffead27 (org.apache.zookeeper.ZooKeeper)", "offset": 372, "prospector.type": "log" @@ -73,6 +78,7 @@ "kafka.log.component": "unknown", "kafka.log.level": "INFO", "kafka.log.message": "Waiting for keeper state SyncConnected", + "log.original": "[2017-08-04 10:48:20,413] INFO Waiting for keeper state SyncConnected (org.I0Itec.zkclient.ZkClient)", "message": "[2017-08-04 10:48:20,413] INFO Waiting for keeper state SyncConnected (org.I0Itec.zkclient.ZkClient)", "offset": 561, "prospector.type": "log" @@ -86,6 +92,7 @@ "kafka.log.component": "unknown", "kafka.log.level": "INFO", "kafka.log.message": "Opening socket connection to server localhost/0:0:0:0:0:0:0:1:2181. Will not attempt to authenticate using SASL (unknown error)", + "log.original": "[2017-08-04 10:48:20,415] INFO Opening socket connection to server localhost/0:0:0:0:0:0:0:1:2181. Will not attempt to authenticate using SASL (unknown error) (org.apache.zookeeper.ClientCnxn)", "message": "[2017-08-04 10:48:20,415] INFO Opening socket connection to server localhost/0:0:0:0:0:0:0:1:2181. Will not attempt to authenticate using SASL (unknown error) (org.apache.zookeeper.ClientCnxn)", "offset": 662, "prospector.type": "log" @@ -99,6 +106,7 @@ "kafka.log.component": "unknown", "kafka.log.level": "INFO", "kafka.log.message": "Socket connection established to localhost/0:0:0:0:0:0:0:1:2181, initiating session", + "log.original": "[2017-08-04 10:48:20,420] INFO Socket connection established to localhost/0:0:0:0:0:0:0:1:2181, initiating session (org.apache.zookeeper.ClientCnxn)", "message": "[2017-08-04 10:48:20,420] INFO Socket connection established to localhost/0:0:0:0:0:0:0:1:2181, initiating session (org.apache.zookeeper.ClientCnxn)", "offset": 855, "prospector.type": "log" @@ -112,6 +120,7 @@ "kafka.log.component": "unknown", "kafka.log.level": "INFO", "kafka.log.message": "Session establishment complete on server localhost/0:0:0:0:0:0:0:1:2181, sessionid = 0x15dabf8d4140000, negotiated timeout = 6000", + "log.original": "[2017-08-04 10:48:20,457] INFO Session establishment complete on server localhost/0:0:0:0:0:0:0:1:2181, sessionid = 0x15dabf8d4140000, negotiated timeout = 6000 (org.apache.zookeeper.ClientCnxn)", "message": "[2017-08-04 10:48:20,457] INFO Session establishment complete on server localhost/0:0:0:0:0:0:0:1:2181, sessionid = 0x15dabf8d4140000, negotiated timeout = 6000 (org.apache.zookeeper.ClientCnxn)", "offset": 1004, "prospector.type": "log" @@ -125,6 +134,7 @@ "kafka.log.component": "unknown", "kafka.log.level": "INFO", "kafka.log.message": "zookeeper state changed (SyncConnected)", + "log.original": "[2017-08-04 10:48:20,458] INFO zookeeper state changed (SyncConnected) (org.I0Itec.zkclient.ZkClient)", "message": "[2017-08-04 10:48:20,458] INFO zookeeper state changed (SyncConnected) (org.I0Itec.zkclient.ZkClient)", "offset": 1199, "prospector.type": "log" @@ -138,6 +148,7 @@ "kafka.log.component": "unknown", "kafka.log.level": "WARN", "kafka.log.message": "No meta.properties file under dir /tmp/kafka-logs/meta.properties", + "log.original": "[2017-08-04 10:48:20,748] WARN No meta.properties file under dir /tmp/kafka-logs/meta.properties (kafka.server.BrokerMetadataCheckpoint)", "message": "[2017-08-04 10:48:20,748] WARN No meta.properties file under dir /tmp/kafka-logs/meta.properties (kafka.server.BrokerMetadataCheckpoint)", "offset": 1301, "prospector.type": "log" @@ -151,6 +162,7 @@ "kafka.log.component": "ThrottledRequestReaper-Fetch", "kafka.log.level": "INFO", "kafka.log.message": "Starting", + "log.original": "[2017-08-04 10:48:20,800] INFO [ThrottledRequestReaper-Fetch]: Starting (kafka.server.ClientQuotaManager$ThrottledRequestReaper)", "message": "[2017-08-04 10:48:20,800] INFO [ThrottledRequestReaper-Fetch]: Starting (kafka.server.ClientQuotaManager$ThrottledRequestReaper)", "offset": 1438, "prospector.type": "log" @@ -164,6 +176,7 @@ "kafka.log.component": "unknown", "kafka.log.level": "INFO", "kafka.log.message": "Log directory '/tmp/kafka-logs' not found, creating it.", + "log.original": "[2017-08-04 10:48:20,866] INFO Log directory '/tmp/kafka-logs' not found, creating it. (kafka.log.LogManager)", "message": "[2017-08-04 10:48:20,866] INFO Log directory '/tmp/kafka-logs' not found, creating it. (kafka.log.LogManager)", "offset": 1567, "prospector.type": "log" @@ -177,6 +190,7 @@ "kafka.log.component": "unknown", "kafka.log.level": "INFO", "kafka.log.message": "Loading logs.", + "log.original": "[2017-08-04 10:48:20,873] INFO Loading logs. (kafka.log.LogManager)", "message": "[2017-08-04 10:48:20,873] INFO Loading logs. (kafka.log.LogManager)", "offset": 1677, "prospector.type": "log" @@ -190,6 +204,7 @@ "kafka.log.component": "ExpirationReaper-0-Heartbeat", "kafka.log.level": "INFO", "kafka.log.message": "Starting", + "log.original": "[2017-08-04 10:48:21,062] INFO [ExpirationReaper-0-Heartbeat]: Starting (kafka.server.DelayedOperationPurgatory$ExpiredOperationReaper)", "message": "[2017-08-04 10:48:21,062] INFO [ExpirationReaper-0-Heartbeat]: Starting (kafka.server.DelayedOperationPurgatory$ExpiredOperationReaper)", "offset": 1745, "prospector.type": "log" @@ -203,6 +218,7 @@ "kafka.log.component": "unknown", "kafka.log.level": "INFO", "kafka.log.message": "Result of znode creation is: OK", + "log.original": "[2017-08-04 10:48:21,063] INFO Result of znode creation is: OK (kafka.utils.ZKCheckedEphemeral)", "message": "[2017-08-04 10:48:21,063] INFO Result of znode creation is: OK (kafka.utils.ZKCheckedEphemeral)", "offset": 1881, "prospector.type": "log" @@ -216,6 +232,7 @@ "kafka.log.component": "Group Metadata Manager on Broker 0", "kafka.log.level": "INFO", "kafka.log.message": "Removed 0 expired offsets in 1 milliseconds.", + "log.original": "[2017-08-04 10:48:21,095] INFO [Group Metadata Manager on Broker 0]: Removed 0 expired offsets in 1 milliseconds. (kafka.coordinator.group.GroupMetadataManager)", "message": "[2017-08-04 10:48:21,095] INFO [Group Metadata Manager on Broker 0]: Removed 0 expired offsets in 1 milliseconds. (kafka.coordinator.group.GroupMetadataManager)", "offset": 1977, "prospector.type": "log" @@ -229,6 +246,7 @@ "kafka.log.component": "ProducerId Manager 0", "kafka.log.level": "INFO", "kafka.log.message": "Acquired new producerId block (brokerId:0,blockStartProducerId:0,blockEndProducerId:999) by writing to Zk with path version 1", + "log.original": "[2017-08-04 10:48:21,127] INFO [ProducerId Manager 0]: Acquired new producerId block (brokerId:0,blockStartProducerId:0,blockEndProducerId:999) by writing to Zk with path version 1 (kafka.coordinator.transaction.ProducerIdManager)", "message": "[2017-08-04 10:48:21,127] INFO [ProducerId Manager 0]: Acquired new producerId block (brokerId:0,blockStartProducerId:0,blockEndProducerId:999) by writing to Zk with path version 1 (kafka.coordinator.transaction.ProducerIdManager)", "offset": 2138, "prospector.type": "log" @@ -242,6 +260,7 @@ "kafka.log.component": "Transaction Coordinator 0", "kafka.log.level": "INFO", "kafka.log.message": "Starting up.", + "log.original": "[2017-08-04 10:48:21,162] INFO [Transaction Coordinator 0]: Starting up. (kafka.coordinator.transaction.TransactionCoordinator)", "message": "[2017-08-04 10:48:21,162] INFO [Transaction Coordinator 0]: Starting up. (kafka.coordinator.transaction.TransactionCoordinator)", "offset": 2369, "prospector.type": "log" @@ -255,6 +274,7 @@ "kafka.log.component": "Transaction Marker Channel Manager 0", "kafka.log.level": "INFO", "kafka.log.message": "Starting", + "log.original": "[2017-08-04 10:48:21,167] INFO [Transaction Marker Channel Manager 0]: Starting (kafka.coordinator.transaction.TransactionMarkerChannelManager)", "message": "[2017-08-04 10:48:21,167] INFO [Transaction Marker Channel Manager 0]: Starting (kafka.coordinator.transaction.TransactionMarkerChannelManager)", "offset": 2497, "prospector.type": "log" diff --git a/filebeat/module/kafka/log/test/state-change-1.1.0.log-expected.json b/filebeat/module/kafka/log/test/state-change-1.1.0.log-expected.json index be011b17d23..e278bb8d83e 100644 --- a/filebeat/module/kafka/log/test/state-change-1.1.0.log-expected.json +++ b/filebeat/module/kafka/log/test/state-change-1.1.0.log-expected.json @@ -8,6 +8,7 @@ "kafka.log.component": "Broker id=30", "kafka.log.level": "TRACE", "kafka.log.message": "Cached leader info PartitionState(controllerEpoch=25, leader=-1, leaderEpoch=15, isr=[10], zkVersion=15, replicas=[10], offlineReplicas=[10]) for partition __consumer_offsets-16 in response to UpdateMetadata request sent by controller 20 epoch 25 with correlation id 8", + "log.original": "[2018-07-16 10:17:06,489] TRACE [Broker id=30] Cached leader info PartitionState(controllerEpoch=25, leader=-1, leaderEpoch=15, isr=[10], zkVersion=15, replicas=[10], offlineReplicas=[10]) for partition __consumer_offsets-16 in response to UpdateMetadata request sent by controller 20 epoch 25 with correlation id 8 (state.change.logger)", "message": "[2018-07-16 10:17:06,489] TRACE [Broker id=30] Cached leader info PartitionState(controllerEpoch=25, leader=-1, leaderEpoch=15, isr=[10], zkVersion=15, replicas=[10], offlineReplicas=[10]) for partition __consumer_offsets-16 in response to UpdateMetadata request sent by controller 20 epoch 25 with correlation id 8 (state.change.logger)", "offset": 0, "prospector.type": "log" diff --git a/filebeat/module/kafka/log/test/state-change.log-expected.json b/filebeat/module/kafka/log/test/state-change.log-expected.json index f6c4112aa1a..c1de02dead2 100644 --- a/filebeat/module/kafka/log/test/state-change.log-expected.json +++ b/filebeat/module/kafka/log/test/state-change.log-expected.json @@ -8,6 +8,7 @@ "kafka.log.component": "unknown", "kafka.log.level": "TRACE", "kafka.log.message": "Controller 0 epoch 1 received response {error_code=0} for a request sent to broker baldur:9092 (id: 0 rack: null)", + "log.original": "[2017-08-04 10:48:21,428] TRACE Controller 0 epoch 1 received response {error_code=0} for a request sent to broker baldur:9092 (id: 0 rack: null) (state.change.logger)", "message": "[2017-08-04 10:48:21,428] TRACE Controller 0 epoch 1 received response {error_code=0} for a request sent to broker baldur:9092 (id: 0 rack: null) (state.change.logger)", "offset": 0, "prospector.type": "log" diff --git a/filebeat/module/logstash/log/test/logstash-plain.log-expected.json b/filebeat/module/logstash/log/test/logstash-plain.log-expected.json index 2157da6003d..05d84e58264 100644 --- a/filebeat/module/logstash/log/test/logstash-plain.log-expected.json +++ b/filebeat/module/logstash/log/test/logstash-plain.log-expected.json @@ -4,6 +4,7 @@ "fileset.module": "logstash", "fileset.name": "log", "input.type": "log", + "log.original": "[2017-10-23T14:20:12,046][INFO ][logstash.modules.scaffold] Initializing module {:module_name=>\"fb_apache\", :directory=>\"/usr/share/logstash/modules/fb_apache/configuration\"}", "logstash.log.level": "INFO", "logstash.log.message": "Initializing module {:module_name=>\"fb_apache\", :directory=>\"/usr/share/logstash/modules/fb_apache/configuration\"}", "logstash.log.module": "logstash.modules.scaffold", diff --git a/filebeat/module/logstash/slowlog/test/slowlog-plain.log-expected.json b/filebeat/module/logstash/slowlog/test/slowlog-plain.log-expected.json index 835106bf975..b8949ecd31a 100644 --- a/filebeat/module/logstash/slowlog/test/slowlog-plain.log-expected.json +++ b/filebeat/module/logstash/slowlog/test/slowlog-plain.log-expected.json @@ -4,6 +4,7 @@ "fileset.module": "logstash", "fileset.name": "slowlog", "input.type": "log", + "log.original": "[2017-10-30T09:57:58,243][WARN ][slowlog.logstash.filters.sleep] event processing time {:plugin_params=>{\"time\"=>3, \"id\"=>\"e4e12a4e3082615c5427079bf4250dbfa338ebac10f8ea9912d7b98a14f56b8c\"}, :took_in_nanos=>3027675106, :took_in_millis=>3027, :event=>\"{\\\"@version\\\":\\\"1\\\",\\\"@timestamp\\\":\\\"2017-10-30T13:57:55.130Z\\\",\\\"host\\\":\\\"sashimi\\\",\\\"sequence\\\":0,\\\"message\\\":\\\"Hello world!\\\"}\"}", "logstash.slowlog.event": "\"{\\\"@version\\\":\\\"1\\\",\\\"@timestamp\\\":\\\"2017-10-30T13:57:55.130Z\\\",\\\"host\\\":\\\"sashimi\\\",\\\"sequence\\\":0,\\\"message\\\":\\\"Hello world!\\\"}\"", "logstash.slowlog.level": "WARN", "logstash.slowlog.message": "event processing time {:plugin_params=>{\"time\"=>3, \"id\"=>\"e4e12a4e3082615c5427079bf4250dbfa338ebac10f8ea9912d7b98a14f56b8c\"}, :took_in_nanos=>3027675106, :took_in_millis=>3027, :event=>\"{\\\"@version\\\":\\\"1\\\",\\\"@timestamp\\\":\\\"2017-10-30T13:57:55.130Z\\\",\\\"host\\\":\\\"sashimi\\\",\\\"sequence\\\":0,\\\"message\\\":\\\"Hello world!\\\"}\"}", diff --git a/filebeat/module/mongodb/_meta/config.reference.yml b/filebeat/module/mongodb/_meta/config.reference.yml index 86f1511ec35..615dc97e012 100644 --- a/filebeat/module/mongodb/_meta/config.reference.yml +++ b/filebeat/module/mongodb/_meta/config.reference.yml @@ -10,3 +10,5 @@ # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true diff --git a/filebeat/module/mongodb/log/test/mongodb-debian-3.2.11.log-expected.json b/filebeat/module/mongodb/log/test/mongodb-debian-3.2.11.log-expected.json index f0cd77888db..0b20762f993 100644 --- a/filebeat/module/mongodb/log/test/mongodb-debian-3.2.11.log-expected.json +++ b/filebeat/module/mongodb/log/test/mongodb-debian-3.2.11.log-expected.json @@ -4,6 +4,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:44:56.657+0100 I CONTROL [initandlisten] git version: 009580ad490190ba33d1c6253ebd8d91808923e4", "mongodb.log.component": "CONTROL", "mongodb.log.context": "initandlisten", "mongodb.log.message": "git version: 009580ad490190ba33d1c6253ebd8d91808923e4", @@ -16,6 +17,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:44:56.657+0100 I CONTROL [initandlisten] modules: none", "mongodb.log.component": "CONTROL", "mongodb.log.context": "initandlisten", "mongodb.log.message": "modules: none", @@ -28,6 +30,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:44:56.657+0100 I CONTROL [initandlisten] OpenSSL version: OpenSSL 1.0.2l 25 May 2017", "mongodb.log.component": "CONTROL", "mongodb.log.context": "initandlisten", "mongodb.log.message": "OpenSSL version: OpenSSL 1.0.2l 25 May 2017", @@ -40,6 +43,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:44:56.677+0100 I STORAGE [initandlisten] wiredtiger_open config: create,cache_size=8G,session_max=20000,eviction=(threads_max=4),config_base=false,statistics=(fast),log=(enabled=true,archive=true,path=journal,compressor=snappy),file_manager=(close_idle_time=100000),checkpoint=(wait=60,log_size=2GB),statistics_log=(wait=0),", "mongodb.log.component": "STORAGE", "mongodb.log.context": "initandlisten", "mongodb.log.message": "wiredtiger_open config: create,cache_size=8G,session_max=20000,eviction=(threads_max=4),config_base=false,statistics=(fast),log=(enabled=true,archive=true,path=journal,compressor=snappy),file_manager=(close_idle_time=100000),checkpoint=(wait=60,log_size=2GB),statistics_log=(wait=0),", @@ -52,6 +56,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:44:56.724+0100 I FTDC [initandlisten] Initializing full-time diagnostic data capture with directory '/var/lib/mongodb/diagnostic.data'", "mongodb.log.component": "FTDC", "mongodb.log.context": "initandlisten", "mongodb.log.message": "Initializing full-time diagnostic data capture with directory '/var/lib/mongodb/diagnostic.data'", @@ -64,6 +69,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:44:56.724+0100 I NETWORK [HostnameCanonicalizationWorker] Starting hostname canonicalization worker", "mongodb.log.component": "NETWORK", "mongodb.log.context": "HostnameCanonicalizationWorker", "mongodb.log.message": "Starting hostname canonicalization worker", @@ -76,6 +82,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:44:56.744+0100 I NETWORK [initandlisten] waiting for connections on port 27017", "mongodb.log.component": "NETWORK", "mongodb.log.context": "initandlisten", "mongodb.log.message": "waiting for connections on port 27017", @@ -88,6 +95,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:50:55.170+0100 I NETWORK [conn1] end connection 127.0.0.1:55404 (0 connections now open)", "mongodb.log.component": "NETWORK", "mongodb.log.context": "conn1", "mongodb.log.message": "end connection 127.0.0.1:55404 (0 connections now open)", @@ -100,6 +108,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:50:55.487+0100 I NETWORK [initandlisten] connection accepted from 127.0.0.1:55406 #2 (1 connection now open)", "mongodb.log.component": "NETWORK", "mongodb.log.context": "initandlisten", "mongodb.log.message": "connection accepted from 127.0.0.1:55406 #2 (1 connection now open)", @@ -112,6 +121,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T14:49:45.606+0100 I CONTROL [signalProcessingThread] now exiting", "mongodb.log.component": "CONTROL", "mongodb.log.context": "signalProcessingThread", "mongodb.log.message": "now exiting", @@ -124,6 +134,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T14:49:45.606+0100 I NETWORK [signalProcessingThread] closing listening socket: 7", "mongodb.log.component": "NETWORK", "mongodb.log.context": "signalProcessingThread", "mongodb.log.message": "closing listening socket: 7", @@ -136,6 +147,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T14:49:45.606+0100 I NETWORK [signalProcessingThread] removing socket file: /run/mongodb/mongodb-27017.sock", "mongodb.log.component": "NETWORK", "mongodb.log.context": "signalProcessingThread", "mongodb.log.message": "removing socket file: /run/mongodb/mongodb-27017.sock", @@ -148,6 +160,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T14:49:45.606+0100 I NETWORK [signalProcessingThread] shutdown: going to flush diaglog...", "mongodb.log.component": "NETWORK", "mongodb.log.context": "signalProcessingThread", "mongodb.log.message": "shutdown: going to flush diaglog...", @@ -160,6 +173,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T14:49:45.606+0100 I NETWORK [signalProcessingThread] shutdown: going to close sockets...", "mongodb.log.component": "NETWORK", "mongodb.log.context": "signalProcessingThread", "mongodb.log.message": "shutdown: going to close sockets...", @@ -172,6 +186,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T14:49:45.688+0100 I STORAGE [signalProcessingThread] shutdown: removing fs lock...", "mongodb.log.component": "STORAGE", "mongodb.log.context": "signalProcessingThread", "mongodb.log.message": "shutdown: removing fs lock...", @@ -184,6 +199,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:44:56.657+0100 I CONTROL [initandlisten] db version v3.2.11", "mongodb.log.component": "CONTROL", "mongodb.log.context": "initandlisten", "mongodb.log.message": "db version v3.2.11", @@ -196,6 +212,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:44:56.657+0100 I CONTROL [initandlisten] build environment:", "mongodb.log.component": "CONTROL", "mongodb.log.context": "initandlisten", "mongodb.log.message": "build environment:", @@ -208,6 +225,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:44:56.657+0100 I CONTROL [initandlisten] distarch: x86_64", "mongodb.log.component": "CONTROL", "mongodb.log.context": "initandlisten", "mongodb.log.message": " distarch: x86_64", @@ -220,6 +238,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:44:56.657+0100 I CONTROL [initandlisten] options: { config: \"/etc/mongodb.conf\", net: { bindIp: \"127.0.0.1\", unixDomainSocket: { pathPrefix: \"/run/mongodb\" } }, storage: { dbPath: \"/var/lib/mongodb\", journal: { enabled: true } }, systemLog: { destination: \"file\", logAppend: true, path: \"/var/log/mongodb/mongodb.log\" } }", "mongodb.log.component": "CONTROL", "mongodb.log.context": "initandlisten", "mongodb.log.message": "options: { config: \"/etc/mongodb.conf\", net: { bindIp: \"127.0.0.1\", unixDomainSocket: { pathPrefix: \"/run/mongodb\" } }, storage: { dbPath: \"/var/lib/mongodb\", journal: { enabled: true } }, systemLog: { destination: \"file\", logAppend: true, path: \"/var/log/mongodb/mongodb.log\" } }", @@ -232,6 +251,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:50:55.170+0100 I NETWORK [initandlisten] connection accepted from 127.0.0.1:55404 #1 (1 connection now open)", "mongodb.log.component": "NETWORK", "mongodb.log.context": "initandlisten", "mongodb.log.message": "connection accepted from 127.0.0.1:55404 #1 (1 connection now open)", @@ -244,6 +264,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:50:56.180+0100 I NETWORK [conn3] end connection 127.0.0.1:55414 (0 connections now open)", "mongodb.log.component": "NETWORK", "mongodb.log.context": "conn3", "mongodb.log.message": "end connection 127.0.0.1:55414 (0 connections now open)", @@ -256,6 +277,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T14:15:42.095+0100 I NETWORK [conn4] end connection 127.0.0.1:58336 (0 connections now open)", "mongodb.log.component": "NETWORK", "mongodb.log.context": "conn4", "mongodb.log.message": "end connection 127.0.0.1:58336 (0 connections now open)", @@ -268,6 +290,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T14:49:45.606+0100 I NETWORK [signalProcessingThread] shutdown: going to close listening sockets...", "mongodb.log.component": "NETWORK", "mongodb.log.context": "signalProcessingThread", "mongodb.log.message": "shutdown: going to close listening sockets...", @@ -280,6 +303,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T14:49:45.606+0100 I STORAGE [signalProcessingThread] WiredTigerKVEngine shutting down", "mongodb.log.component": "STORAGE", "mongodb.log.context": "signalProcessingThread", "mongodb.log.message": "WiredTigerKVEngine shutting down", @@ -292,6 +316,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T14:49:45.688+0100 I CONTROL [signalProcessingThread] dbexit: rc: 0", "mongodb.log.component": "CONTROL", "mongodb.log.context": "signalProcessingThread", "mongodb.log.message": "dbexit: rc: 0", @@ -304,6 +329,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:44:56.657+0100 I CONTROL [initandlisten] MongoDB starting : pid=29803 port=27017 dbpath=/var/lib/mongodb 64-bit host=sleipnir", "mongodb.log.component": "CONTROL", "mongodb.log.context": "initandlisten", "mongodb.log.message": "MongoDB starting : pid=29803 port=27017 dbpath=/var/lib/mongodb 64-bit host=sleipnir", @@ -316,6 +342,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:44:56.657+0100 I CONTROL [initandlisten] allocator: tcmalloc", "mongodb.log.component": "CONTROL", "mongodb.log.context": "initandlisten", "mongodb.log.message": "allocator: tcmalloc", @@ -328,6 +355,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:44:56.657+0100 I CONTROL [initandlisten] target_arch: x86_64", "mongodb.log.component": "CONTROL", "mongodb.log.context": "initandlisten", "mongodb.log.message": " target_arch: x86_64", @@ -340,6 +368,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:50:55.487+0100 I NETWORK [conn2] end connection 127.0.0.1:55406 (0 connections now open)", "mongodb.log.component": "NETWORK", "mongodb.log.context": "conn2", "mongodb.log.message": "end connection 127.0.0.1:55406 (0 connections now open)", @@ -352,6 +381,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T13:50:56.180+0100 I NETWORK [initandlisten] connection accepted from 127.0.0.1:55414 #3 (1 connection now open)", "mongodb.log.component": "NETWORK", "mongodb.log.context": "initandlisten", "mongodb.log.message": "connection accepted from 127.0.0.1:55414 #3 (1 connection now open)", @@ -364,6 +394,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T14:11:41.401+0100 I NETWORK [initandlisten] connection accepted from 127.0.0.1:58336 #4 (1 connection now open)", "mongodb.log.component": "NETWORK", "mongodb.log.context": "initandlisten", "mongodb.log.message": "connection accepted from 127.0.0.1:58336 #4 (1 connection now open)", @@ -376,6 +407,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T14:49:45.605+0100 I CONTROL [signalProcessingThread] got signal 15 (Terminated), will terminate after current cmd ends", "mongodb.log.component": "CONTROL", "mongodb.log.context": "signalProcessingThread", "mongodb.log.message": "got signal 15 (Terminated), will terminate after current cmd ends", @@ -388,6 +420,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T14:49:45.605+0100 I FTDC [signalProcessingThread] Shutting down full-time diagnostic data capture", "mongodb.log.component": "FTDC", "mongodb.log.context": "signalProcessingThread", "mongodb.log.message": "Shutting down full-time diagnostic data capture", @@ -400,6 +433,7 @@ "fileset.module": "mongodb", "fileset.name": "log", "input.type": "log", + "log.original": "2018-02-05T14:49:45.606+0100 I NETWORK [signalProcessingThread] closing listening socket: 6", "mongodb.log.component": "NETWORK", "mongodb.log.context": "signalProcessingThread", "mongodb.log.message": "closing listening socket: 6", diff --git a/filebeat/module/mysql/_meta/config.reference.yml b/filebeat/module/mysql/_meta/config.reference.yml index 49f1db5e72b..e0615ca9204 100644 --- a/filebeat/module/mysql/_meta/config.reference.yml +++ b/filebeat/module/mysql/_meta/config.reference.yml @@ -10,6 +10,8 @@ # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true # Slow logs #slowlog: @@ -22,3 +24,5 @@ # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true diff --git a/filebeat/module/nginx/_meta/config.reference.yml b/filebeat/module/nginx/_meta/config.reference.yml index 572341217e6..080420be06d 100644 --- a/filebeat/module/nginx/_meta/config.reference.yml +++ b/filebeat/module/nginx/_meta/config.reference.yml @@ -10,6 +10,8 @@ # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true # Error logs #error: @@ -22,3 +24,5 @@ # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true diff --git a/filebeat/module/nginx/access/test/test.log-expected.json b/filebeat/module/nginx/access/test/test.log-expected.json index 0b7cc707111..946290c8e89 100644 --- a/filebeat/module/nginx/access/test/test.log-expected.json +++ b/filebeat/module/nginx/access/test/test.log-expected.json @@ -4,6 +4,7 @@ "fileset.module": "nginx", "fileset.name": "access", "input.type": "log", + "log.original": "10.0.0.2, 10.0.0.1, 127.0.0.1 - - [07/Dec/2016:11:05:07 +0100] \"GET /ocelot HTTP/1.1\" 200 571 \"-\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:49.0) Gecko/20100101 Firefox/49.0\"", "nginx.access.body_sent.bytes": "571", "nginx.access.http_version": "1.1", "nginx.access.method": "GET", @@ -34,6 +35,7 @@ "fileset.module": "nginx", "fileset.name": "access", "input.type": "log", + "log.original": "172.17.0.1 - - [29/May/2017:19:02:48 +0000] \"GET /stringpatch HTTP/1.1\" 404 612 \"-\" \"Mozilla/5.0 (Windows NT 6.1; rv:15.0) Gecko/20120716 Firefox/15.0a2\" \"-\"", "nginx.access.body_sent.bytes": "612", "nginx.access.http_version": "1.1", "nginx.access.method": "GET", @@ -61,6 +63,7 @@ "fileset.module": "nginx", "fileset.name": "access", "input.type": "log", + "log.original": "10.0.0.2, 10.0.0.1, 85.181.35.98 - - [07/Dec/2016:11:05:07 +0100] \"GET /ocelot HTTP/1.1\" 200 571 \"-\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:49.0) Gecko/20100101 Firefox/49.0\"", "nginx.access.body_sent.bytes": "571", "nginx.access.geoip.city_name": "Berlin", "nginx.access.geoip.continent_name": "Europe", @@ -98,6 +101,7 @@ "fileset.module": "nginx", "fileset.name": "access", "input.type": "log", + "log.original": "85.181.35.98 - - [07/Dec/2016:11:05:07 +0100] \"GET /ocelot HTTP/1.1\" 200 571 \"-\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:49.0) Gecko/20100101 Firefox/49.0\"", "nginx.access.body_sent.bytes": "571", "nginx.access.geoip.city_name": "Berlin", "nginx.access.geoip.continent_name": "Europe", @@ -133,6 +137,7 @@ "fileset.module": "nginx", "fileset.name": "access", "input.type": "log", + "log.original": "\"10.5.102.222, 199.96.1.1, 204.246.1.1\" 10.2.1.185 - - [22/Jan/2016:13:18:29 +0000] \"GET /assets/xxxx?q=100 HTTP/1.1\" 200 25507 \"-\" \"Amazon CloudFront\"", "nginx.access.body_sent.bytes": "25507", "nginx.access.geoip.city_name": "Springfield", "nginx.access.geoip.continent_name": "North America", @@ -167,6 +172,7 @@ "fileset.module": "nginx", "fileset.name": "access", "input.type": "log", + "log.original": "2a03:0000:10ff:f00f:0000:0000:0:8000, 10.225.192.17 10.2.2.121 - - [30/Dec/2016:06:47:09 +0000] \"GET /test.html HTTP/1.1\" 404 8571 \"-\" \"Mozilla/5.0 (compatible; Facebot 1.0; https://developers.facebook.com/docs/sharing/webmasters/crawler)\"", "nginx.access.body_sent.bytes": "8571", "nginx.access.geoip.continent_name": "Europe", "nginx.access.geoip.country_iso_code": "PT", @@ -199,6 +205,7 @@ "fileset.module": "nginx", "fileset.name": "access", "input.type": "log", + "log.original": "127.0.0.1 - - [12/Apr/2018:09:48:40 +0200] \"\" 400 0 \"-\" \"-\"", "nginx.access.body_sent.bytes": "0", "nginx.access.referrer": "-", "nginx.access.remote_ip": "127.0.0.1", diff --git a/filebeat/module/postgresql/_meta/config.reference.yml b/filebeat/module/postgresql/_meta/config.reference.yml index e1deee0e25c..3b0f394d12b 100644 --- a/filebeat/module/postgresql/_meta/config.reference.yml +++ b/filebeat/module/postgresql/_meta/config.reference.yml @@ -10,3 +10,5 @@ # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true diff --git a/filebeat/module/postgresql/log/test/postgresql-9.6-debian-with-slowlog.log-expected.json b/filebeat/module/postgresql/log/test/postgresql-9.6-debian-with-slowlog.log-expected.json index b17481ca76b..47eae945f66 100644 --- a/filebeat/module/postgresql/log/test/postgresql-9.6-debian-with-slowlog.log-expected.json +++ b/filebeat/module/postgresql/log/test/postgresql-9.6-debian-with-slowlog.log-expected.json @@ -4,6 +4,7 @@ "fileset.module": "postgresql", "fileset.name": "log", "input.type": "log", + "log.original": "2017-07-31 13:36:42.585 CEST [4974] LOG: database system was shut down at 2017-06-17 16:58:04 CEST", "message": "2017-07-31 13:36:42.585 CEST [4974] LOG: database system was shut down at 2017-06-17 16:58:04 CEST", "offset": 0, "postgresql.log.level": "LOG", @@ -18,6 +19,7 @@ "fileset.module": "postgresql", "fileset.name": "log", "input.type": "log", + "log.original": "2017-07-31 13:36:42.605 CEST [4974] LOG: MultiXact member wraparound protections are now enabled", "message": "2017-07-31 13:36:42.605 CEST [4974] LOG: MultiXact member wraparound protections are now enabled", "offset": 100, "postgresql.log.level": "LOG", @@ -32,6 +34,7 @@ "fileset.module": "postgresql", "fileset.name": "log", "input.type": "log", + "log.original": "2017-07-31 13:36:42.615 CEST [4978] LOG: autovacuum launcher started", "message": "2017-07-31 13:36:42.615 CEST [4978] LOG: autovacuum launcher started", "offset": 198, "postgresql.log.level": "LOG", @@ -46,6 +49,7 @@ "fileset.module": "postgresql", "fileset.name": "log", "input.type": "log", + "log.original": "2017-07-31 13:36:42.616 CEST [4973] LOG: database system is ready to accept connections", "message": "2017-07-31 13:36:42.616 CEST [4973] LOG: database system is ready to accept connections", "offset": 268, "postgresql.log.level": "LOG", @@ -60,6 +64,7 @@ "fileset.module": "postgresql", "fileset.name": "log", "input.type": "log", + "log.original": "2017-07-31 13:36:42.956 CEST [4980] [unknown]@[unknown] LOG: incomplete startup packet", "message": "2017-07-31 13:36:42.956 CEST [4980] [unknown]@[unknown] LOG: incomplete startup packet", "offset": 357, "postgresql.log.database": "unknown", @@ -79,6 +84,7 @@ "log.flags": [ "multiline" ], + "log.original": "2017-07-31 13:36:43.557 CEST [4983] postgres@postgres LOG: duration: 37.118 ms statement: SELECT d.datname as \"Name\",\n\t pg_catalog.pg_get_userbyid(d.datdba) as \"Owner\",\n\t pg_catalog.pg_encoding_to_char(d.encoding) as \"Encoding\",\n\t d.datcollate as \"Collate\",\n\t d.datctype as \"Ctype\",\n\t pg_catalog.array_to_string(d.datacl, E'\\n') AS \"Access privileges\"\n\tFROM pg_catalog.pg_database d\n\tORDER BY 1;", "message": "2017-07-31 13:36:43.557 CEST [4983] postgres@postgres LOG: duration: 37.118 ms statement: SELECT d.datname as \"Name\",\n\t pg_catalog.pg_get_userbyid(d.datdba) as \"Owner\",\n\t pg_catalog.pg_encoding_to_char(d.encoding) as \"Encoding\",\n\t d.datcollate as \"Collate\",\n\t d.datctype as \"Ctype\",\n\t pg_catalog.array_to_string(d.datacl, E'\\n') AS \"Access privileges\"\n\tFROM pg_catalog.pg_database d\n\tORDER BY 1;", "offset": 445, "postgresql.log.database": "postgres", @@ -99,6 +105,7 @@ "log.flags": [ "multiline" ], + "log.original": "2017-07-31 13:36:44.104 CEST [4986] postgres@postgres LOG: duration: 2.895 ms statement: SELECT d.datname as \"Name\",\n\t pg_catalog.pg_get_userbyid(d.datdba) as \"Owner\",\n\t pg_catalog.pg_encoding_to_char(d.encoding) as \"Encoding\",\n\t d.datcollate as \"Collate\",\n\t d.datctype as \"Ctype\",\n\t pg_catalog.array_to_string(d.datacl, E'\\n') AS \"Access privileges\"\n\tFROM pg_catalog.pg_database d\n\tORDER BY 1;", "message": "2017-07-31 13:36:44.104 CEST [4986] postgres@postgres LOG: duration: 2.895 ms statement: SELECT d.datname as \"Name\",\n\t pg_catalog.pg_get_userbyid(d.datdba) as \"Owner\",\n\t pg_catalog.pg_encoding_to_char(d.encoding) as \"Encoding\",\n\t d.datcollate as \"Collate\",\n\t d.datctype as \"Ctype\",\n\t pg_catalog.array_to_string(d.datacl, E'\\n') AS \"Access privileges\"\n\tFROM pg_catalog.pg_database d\n\tORDER BY 1;", "offset": 873, "postgresql.log.database": "postgres", @@ -119,6 +126,7 @@ "log.flags": [ "multiline" ], + "log.original": "2017-07-31 13:36:44.642 CEST [4989] postgres@postgres LOG: duration: 2.809 ms statement: SELECT d.datname as \"Name\",\n\t pg_catalog.pg_get_userbyid(d.datdba) as \"Owner\",\n\t pg_catalog.pg_encoding_to_char(d.encoding) as \"Encoding\",\n\t d.datcollate as \"Collate\",\n\t d.datctype as \"Ctype\",\n\t pg_catalog.array_to_string(d.datacl, E'\\n') AS \"Access privileges\"\n\tFROM pg_catalog.pg_database d\n\tORDER BY 1;", "message": "2017-07-31 13:36:44.642 CEST [4989] postgres@postgres LOG: duration: 2.809 ms statement: SELECT d.datname as \"Name\",\n\t pg_catalog.pg_get_userbyid(d.datdba) as \"Owner\",\n\t pg_catalog.pg_encoding_to_char(d.encoding) as \"Encoding\",\n\t d.datcollate as \"Collate\",\n\t d.datctype as \"Ctype\",\n\t pg_catalog.array_to_string(d.datacl, E'\\n') AS \"Access privileges\"\n\tFROM pg_catalog.pg_database d\n\tORDER BY 1;", "offset": 1300, "postgresql.log.database": "postgres", @@ -136,6 +144,7 @@ "fileset.module": "postgresql", "fileset.name": "log", "input.type": "log", + "log.original": "2017-07-31 13:39:16.249 CEST [5407] postgres@users FATAL: database \"users\" does not exist", "message": "2017-07-31 13:39:16.249 CEST [5407] postgres@users FATAL: database \"users\" does not exist", "offset": 1727, "postgresql.log.database": "users", @@ -152,6 +161,7 @@ "fileset.module": "postgresql", "fileset.name": "log", "input.type": "log", + "log.original": "2017-07-31 13:39:17.945 CEST [5500] postgres@user FATAL: database \"user\" does not exist", "message": "2017-07-31 13:39:17.945 CEST [5500] postgres@user FATAL: database \"user\" does not exist", "offset": 1818, "postgresql.log.database": "user", @@ -171,6 +181,7 @@ "log.flags": [ "multiline" ], + "log.original": "2017-07-31 13:39:21.025 CEST [5404] postgres@postgres LOG: duration: 37.598 ms statement: SELECT n.nspname as \"Schema\",\n\t c.relname as \"Name\",\n\t CASE c.relkind WHEN 'r' THEN 'table' WHEN 'v' THEN 'view' WHEN 'm' THEN 'materialized view' WHEN 'i' THEN 'index' WHEN 'S' THEN 'sequence' WHEN 's' THEN 'special' WHEN 'f' THEN 'foreign table' END as \"Type\",\n\t pg_catalog.pg_get_userbyid(c.relowner) as \"Owner\"\n\tFROM pg_catalog.pg_class c\n\t LEFT JOIN pg_catalog.pg_namespace n ON n.oid = c.relnamespace\n\tWHERE c.relkind IN ('r','')\n\t AND n.nspname <> 'pg_catalog'\n\t AND n.nspname <> 'information_schema'\n\t AND n.nspname !~ '^pg_toast'\n\t AND pg_catalog.pg_table_is_visible(c.oid)\n\tORDER BY 1,2;", "message": "2017-07-31 13:39:21.025 CEST [5404] postgres@postgres LOG: duration: 37.598 ms statement: SELECT n.nspname as \"Schema\",\n\t c.relname as \"Name\",\n\t CASE c.relkind WHEN 'r' THEN 'table' WHEN 'v' THEN 'view' WHEN 'm' THEN 'materialized view' WHEN 'i' THEN 'index' WHEN 'S' THEN 'sequence' WHEN 's' THEN 'special' WHEN 'f' THEN 'foreign table' END as \"Type\",\n\t pg_catalog.pg_get_userbyid(c.relowner) as \"Owner\"\n\tFROM pg_catalog.pg_class c\n\t LEFT JOIN pg_catalog.pg_namespace n ON n.oid = c.relnamespace\n\tWHERE c.relkind IN ('r','')\n\t AND n.nspname <> 'pg_catalog'\n\t AND n.nspname <> 'information_schema'\n\t AND n.nspname !~ '^pg_toast'\n\t AND pg_catalog.pg_table_is_visible(c.oid)\n\tORDER BY 1,2;", "offset": 1907, "postgresql.log.database": "postgres", @@ -188,6 +199,7 @@ "fileset.module": "postgresql", "fileset.name": "log", "input.type": "log", + "log.original": "2017-07-31 13:39:31.619 CEST [5502] postgres@clients LOG: duration: 9.482 ms statement: select * from clients;", "message": "2017-07-31 13:39:31.619 CEST [5502] postgres@clients LOG: duration: 9.482 ms statement: select * from clients;", "offset": 2620, "postgresql.log.database": "clients", @@ -205,6 +217,7 @@ "fileset.module": "postgresql", "fileset.name": "log", "input.type": "log", + "log.original": "2017-07-31 13:39:40.147 CEST [5502] postgres@clients LOG: duration: 0.765 ms statement: select id from clients;", "message": "2017-07-31 13:39:40.147 CEST [5502] postgres@clients LOG: duration: 0.765 ms statement: select id from clients;", "offset": 2733, "postgresql.log.database": "clients", @@ -225,6 +238,7 @@ "log.flags": [ "multiline" ], + "log.original": "2017-07-31 13:40:54.310 CEST [5502] postgres@clients LOG: duration: 26.082 ms statement: SELECT n.nspname as \"Schema\",\n\t c.relname as \"Name\",\n\t CASE c.relkind WHEN 'r' THEN 'table' WHEN 'v' THEN 'view' WHEN 'm' THEN 'materialized view' WHEN 'i' THEN 'index' WHEN 'S' THEN 'sequence' WHEN 's' THEN 'special' WHEN 'f' THEN 'foreign table' END as \"Type\",\n\t pg_catalog.pg_get_userbyid(c.relowner) as \"Owner\"\n\tFROM pg_catalog.pg_class c\n\t LEFT JOIN pg_catalog.pg_namespace n ON n.oid = c.relnamespace\n\tWHERE c.relkind IN ('r','')\n\t AND n.nspname <> 'pg_catalog'\n\t AND n.nspname <> 'information_schema'\n\t AND n.nspname !~ '^pg_toast'\n\t AND pg_catalog.pg_table_is_visible(c.oid)\n\tORDER BY 1,2;", "message": "2017-07-31 13:40:54.310 CEST [5502] postgres@clients LOG: duration: 26.082 ms statement: SELECT n.nspname as \"Schema\",\n\t c.relname as \"Name\",\n\t CASE c.relkind WHEN 'r' THEN 'table' WHEN 'v' THEN 'view' WHEN 'm' THEN 'materialized view' WHEN 'i' THEN 'index' WHEN 'S' THEN 'sequence' WHEN 's' THEN 'special' WHEN 'f' THEN 'foreign table' END as \"Type\",\n\t pg_catalog.pg_get_userbyid(c.relowner) as \"Owner\"\n\tFROM pg_catalog.pg_class c\n\t LEFT JOIN pg_catalog.pg_namespace n ON n.oid = c.relnamespace\n\tWHERE c.relkind IN ('r','')\n\t AND n.nspname <> 'pg_catalog'\n\t AND n.nspname <> 'information_schema'\n\t AND n.nspname !~ '^pg_toast'\n\t AND pg_catalog.pg_table_is_visible(c.oid)\n\tORDER BY 1,2;", "offset": 2847, "postgresql.log.database": "clients", @@ -242,6 +256,7 @@ "fileset.module": "postgresql", "fileset.name": "log", "input.type": "log", + "log.original": "2017-07-31 13:43:22.645 CEST [5502] postgres@clients LOG: duration: 36.162 ms statement: create table cats(name varchar(50) primary key, toy varchar (50) not null, born timestamp not null);", "message": "2017-07-31 13:43:22.645 CEST [5502] postgres@clients LOG: duration: 36.162 ms statement: create table cats(name varchar(50) primary key, toy varchar (50) not null, born timestamp not null);", "offset": 3559, "postgresql.log.database": "clients", @@ -259,6 +274,7 @@ "fileset.module": "postgresql", "fileset.name": "log", "input.type": "log", + "log.original": "2017-07-31 13:46:02.670 CEST [5502] postgres@c$lients LOG: duration: 10.540 ms statement: insert into cats(name, toy, born) values('kate', 'ball', now());", "message": "2017-07-31 13:46:02.670 CEST [5502] postgres@c$lients LOG: duration: 10.540 ms statement: insert into cats(name, toy, born) values('kate', 'ball', now());", "offset": 3751, "postgresql.log.database": "c$lients", @@ -276,6 +292,7 @@ "fileset.module": "postgresql", "fileset.name": "log", "input.type": "log", + "log.original": "2017-07-31 13:46:23.016 CEST [5502] postgres@_clients$db LOG: duration: 5.156 ms statement: insert into cats(name, toy, born) values('frida', 'horse', now());", "message": "2017-07-31 13:46:23.016 CEST [5502] postgres@_clients$db LOG: duration: 5.156 ms statement: insert into cats(name, toy, born) values('frida', 'horse', now());", "offset": 3908, "postgresql.log.database": "_clients$db", @@ -293,6 +310,7 @@ "fileset.module": "postgresql", "fileset.name": "log", "input.type": "log", + "log.original": "2017-07-31 13:46:55.637 CEST [5502] postgres@clients_db LOG: duration: 25.871 ms statement: create table dogs(name varchar(50) primary key, owner varchar (50) not null, born timestamp not null);", "message": "2017-07-31 13:46:55.637 CEST [5502] postgres@clients_db LOG: duration: 25.871 ms statement: create table dogs(name varchar(50) primary key, owner varchar (50) not null, born timestamp not null);", "offset": 4069, "postgresql.log.database": "clients_db", diff --git a/filebeat/module/redis/log/test/test.log-expected.json b/filebeat/module/redis/log/test/test.log-expected.json index 3fd7f8f3454..654bce00928 100644 --- a/filebeat/module/redis/log/test/test.log-expected.json +++ b/filebeat/module/redis/log/test/test.log-expected.json @@ -4,6 +4,7 @@ "fileset.module": "redis", "fileset.name": "log", "input.type": "log", + "log.original": "98738:M 30 May 12:23:52.442 * Saving the final RDB snapshot before exiting.", "offset": 0, "prospector.type": "log", "redis.log.level": "notice", @@ -16,6 +17,7 @@ "fileset.module": "redis", "fileset.name": "log", "input.type": "log", + "log.original": "30 May 10:05:20 . 0 clients connected (0 slaves), 618932 bytes in use, 0 shared objects.", "offset": 76, "prospector.type": "log", "redis.log.level": "debug", @@ -26,6 +28,7 @@ "fileset.module": "redis", "fileset.name": "log", "input.type": "log", + "log.original": "[2932] 31 May 04:32:08 * The server is now ready to accept connections on port 6379\"", "offset": 165, "prospector.type": "log", "redis.log.level": "notice", @@ -36,6 +39,7 @@ "fileset.module": "redis", "fileset.name": "log", "input.type": "log", + "log.original": "5092:signal-handler (1496141844) Received SIGINT scheduling shutdown...", "offset": 250, "prospector.type": "log", "redis.log.message": "Received SIGINT scheduling shutdown...", diff --git a/filebeat/module/system/_meta/config.reference.yml b/filebeat/module/system/_meta/config.reference.yml index b4121ca8081..24bb3d77be7 100644 --- a/filebeat/module/system/_meta/config.reference.yml +++ b/filebeat/module/system/_meta/config.reference.yml @@ -13,6 +13,8 @@ # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true # Authorization logs #auth: @@ -28,3 +30,5 @@ # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true diff --git a/filebeat/module/system/auth/test/test.log-expected.json b/filebeat/module/system/auth/test/test.log-expected.json index c99cbeb2fa3..cd75299b6f8 100644 --- a/filebeat/module/system/auth/test/test.log-expected.json +++ b/filebeat/module/system/auth/test/test.log-expected.json @@ -4,6 +4,7 @@ "fileset.module": "system", "fileset.name": "auth", "input.type": "log", + "log.original": "Feb 21 21:54:44 localhost sshd[3402]: Accepted publickey for vagrant from 10.0.2.2 port 63673 ssh2: RSA 39:33:99:e9:a0:dc:f2:33:a3:e5:72:3b:7c:3a:56:84", "offset": 0, "prospector.type": "log", "system.auth.hostname": "localhost", @@ -21,6 +22,7 @@ "fileset.module": "system", "fileset.name": "auth", "input.type": "log", + "log.original": "Feb 23 00:13:35 localhost sshd[7483]: Accepted password for vagrant from 192.168.33.1 port 58803 ssh2", "offset": 152, "prospector.type": "log", "system.auth.hostname": "localhost", @@ -37,6 +39,7 @@ "fileset.module": "system", "fileset.name": "auth", "input.type": "log", + "log.original": "Feb 21 21:56:12 localhost sshd[3430]: Invalid user test from 10.0.2.2", "offset": 254, "prospector.type": "log", "system.auth.hostname": "localhost", @@ -51,6 +54,7 @@ "fileset.module": "system", "fileset.name": "auth", "input.type": "log", + "log.original": "Feb 20 08:35:22 slave22 sshd[5774]: Failed password for root from 116.31.116.24 port 29160 ssh2", "offset": 324, "prospector.type": "log", "system.auth.hostname": "slave22", @@ -73,6 +77,7 @@ "fileset.module": "system", "fileset.name": "auth", "input.type": "log", + "log.original": "Feb 21 23:35:33 localhost sudo: vagrant : TTY=pts/0 ; PWD=/home/vagrant ; USER=root ; COMMAND=/bin/ls", "offset": 420, "prospector.type": "log", "system.auth.hostname": "localhost", @@ -88,6 +93,7 @@ "fileset.module": "system", "fileset.name": "auth", "input.type": "log", + "log.original": "Feb 19 15:30:04 slave22 sshd[18406]: Did not receive identification string from 123.57.245.163", "offset": 522, "prospector.type": "log", "system.auth.hostname": "slave22", @@ -100,6 +106,7 @@ "fileset.module": "system", "fileset.name": "auth", "input.type": "log", + "log.original": "Feb 23 00:08:48 localhost sudo: vagrant : TTY=pts/1 ; PWD=/home/vagrant ; USER=root ; COMMAND=/bin/cat /var/log/secure", "offset": 617, "prospector.type": "log", "system.auth.hostname": "localhost", @@ -115,6 +122,7 @@ "fileset.module": "system", "fileset.name": "auth", "input.type": "log", + "log.original": "Feb 24 00:13:02 precise32 sudo: tsg : user NOT in sudoers ; TTY=pts/1 ; PWD=/home/vagrant ; USER=root ; COMMAND=/bin/ls", "offset": 736, "prospector.type": "log", "system.auth.hostname": "precise32", @@ -131,6 +139,7 @@ "fileset.module": "system", "fileset.name": "auth", "input.type": "log", + "log.original": "Feb 22 11:47:05 localhost groupadd[6991]: new group: name=apache, GID=48", "offset": 861, "prospector.type": "log", "system.auth.groupadd.gid": "48", @@ -144,6 +153,7 @@ "fileset.module": "system", "fileset.name": "auth", "input.type": "log", + "log.original": "Feb 22 11:47:05 localhost useradd[6995]: new user: name=apache, UID=48, GID=48, home=/usr/share/httpd, shell=/sbin/nologin", "offset": 934, "prospector.type": "log", "system.auth.hostname": "localhost", diff --git a/filebeat/module/system/syslog/test/darwin-syslog-sample.log-expected.json b/filebeat/module/system/syslog/test/darwin-syslog-sample.log-expected.json index 4d667d28a17..b34206989f4 100644 --- a/filebeat/module/system/syslog/test/darwin-syslog-sample.log-expected.json +++ b/filebeat/module/system/syslog/test/darwin-syslog-sample.log-expected.json @@ -7,6 +7,7 @@ "log.flags": [ "multiline" ], + "log.original": "Dec 13 11:35:28 a-mac-with-esc-key GoogleSoftwareUpdateAgent[21412]: 2016-12-13 11:35:28.420 GoogleSoftwareUpdateAgent[21412/0x700007399000] [lvl=2] -[KSAgentApp updateProductWithProductID:usingEngine:] Checking for updates for \"All Products\" using engine \n\t\t>>\n\t\tprocessor=\n\t\t\tisProcessing=NO actionsCompleted=0 progress=0.00\n\t\t\terrors=0 currentActionErrors=0\n\t\t\tevents=0 currentActionEvents=0\n\t\t\tactionQueue=( )\n\t\t>\n\t\tdelegate=(null)\n\t\tserverInfoStore=(null)\n\t\terrors=0\n\t>", "offset": 0, "prospector.type": "log", "system.syslog.hostname": "a-mac-with-esc-key", @@ -20,6 +21,7 @@ "fileset.module": "system", "fileset.name": "syslog", "input.type": "log", + "log.original": "Dec 13 11:35:28 a-mac-with-esc-key GoogleSoftwareUpdateAgent[21412]: 2016-12-13 11:35:28.421 GoogleSoftwareUpdateAgent[21412/0x700007399000] [lvl=2] -[KSUpdateEngine updateAllExceptProduct:] KSUpdateEngine updating all installed products, except:'com.google.Keystone'.", "offset": 907, "prospector.type": "log", "system.syslog.hostname": "a-mac-with-esc-key", @@ -33,6 +35,7 @@ "fileset.module": "system", "fileset.name": "syslog", "input.type": "log", + "log.original": "Apr 4 03:39:57 --- last message repeated 1 time ---", "offset": 1176, "prospector.type": "log", "system.syslog.message": "--- last message repeated 1 time ---", diff --git a/filebeat/module/traefik/_meta/config.reference.yml b/filebeat/module/traefik/_meta/config.reference.yml index e800f73557c..e5a722132a0 100644 --- a/filebeat/module/traefik/_meta/config.reference.yml +++ b/filebeat/module/traefik/_meta/config.reference.yml @@ -10,3 +10,5 @@ # Input configuration (advanced). Any input configuration option # can be added under this section. #input: + #Keeps the original message, so the data can be processed again on Ingest Node. + #keep_original_message: true diff --git a/filebeat/module/traefik/access/test/test.log-expected.json b/filebeat/module/traefik/access/test/test.log-expected.json index 5d9df6d2854..fb07bc96c6d 100644 --- a/filebeat/module/traefik/access/test/test.log-expected.json +++ b/filebeat/module/traefik/access/test/test.log-expected.json @@ -4,6 +4,7 @@ "fileset.module": "traefik", "fileset.name": "access", "input.type": "log", + "log.original": "192.168.33.1 - - [02/Oct/2017:20:22:07 +0000] \"GET /ui/favicons/favicon-16x16.png HTTP/1.1\" 304 0 \"http://example.com/login\" \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36\" 262 \"Host-host-1\" \"http://172.19.0.3:5601\" 2ms", "offset": 0, "prospector.type": "log", "traefik.access.body_sent.bytes": "0", @@ -28,6 +29,7 @@ "fileset.module": "traefik", "fileset.name": "access", "input.type": "log", + "log.original": "85.181.35.98 - - [02/Oct/2017:20:22:08 +0000] \"GET /ui/favicons/favicon.ico HTTP/1.1\" 304 0 \"http://example.com/login\" \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36\" 271 \"Host-host1 \"http://172.19.0.3:5601\" 3ms", "offset": 280, "prospector.type": "log", "traefik.access.body_sent.bytes": "0", diff --git a/libbeat/beat/pipeline.go b/libbeat/beat/pipeline.go index 823ae8de20b..de7d26535fc 100644 --- a/libbeat/beat/pipeline.go +++ b/libbeat/beat/pipeline.go @@ -54,6 +54,9 @@ type ClientConfig struct { // DynamicFields provides additional fields to be added to every event, supporting live updates DynamicFields *common.MapStrPointer + // KeepOriginalMsg determines whether an outgoing event needs to include the original log message. + KeepOriginalMsg bool + // Processors passes additional processor to the client, to be executed before // the pipeline processors. Processor ProcessorList diff --git a/libbeat/publisher/pipeline/processor.go b/libbeat/publisher/pipeline/processor.go index e2dcb7c73c0..a7943ca6029 100644 --- a/libbeat/publisher/pipeline/processor.go +++ b/libbeat/publisher/pipeline/processor.go @@ -48,14 +48,15 @@ type processorFn struct { // // 1. (P) generalize/normalize event // 2. (C) add Meta from client Config to event.Meta -// 3. (C) add Fields from client config to event.Fields -// 4. (P) add pipeline fields + tags -// 5. (C) add client fields + tags -// 6. (C) client processors list -// 7. (P) add beats metadata -// 8. (P) pipeline processors list -// 9. (P) (if publish/debug enabled) log event -// 10. (P) (if output disabled) dropEvent +// 3. (P) copy contents of message to `log.original` +// 4. (C) add Fields from client config to event.Fields +// 5. (P) add pipeline fields + tags +// 6. (C) add client fields + tags +// 7. (C) client processors list +// 8. (P) add beats metadata +// 9. (P) pipeline processors list +// 10. (P) (if publish/debug enabled) log event +// 11. (P) (if output disabled) dropEvent func newProcessorPipeline( info beat.Info, global pipelineProcessors, @@ -82,6 +83,11 @@ func newProcessorPipeline( processors.add(clientEventMeta(m, needsCopy)) } + if config.KeepOriginalMsg { + // setup 3: keep original message + processors.add(keepOriginalMsgProcessor) + } + // setup 4, 5: pipeline tags + client tags var tags []string tags = append(tags, global.tags...) @@ -217,6 +223,17 @@ var dropDisabledProcessor = newProcessor("dropDisabled", func(event *beat.Event) return nil, nil }) +var keepOriginalMsgProcessor = newProcessor("keepOriginalMsgEvent", func(event *beat.Event) (*beat.Event, error) { + // skip event if there is no message + original, ok := event.Fields["message"] + if !ok { + return event, nil + } + + event.PutValue("log.original", original) + return event, nil +}) + func beatAnnotateProcessor(beatMeta common.MapStr) *processorFn { const key = "beat" return newAnnotateProcessor("annotateBeat", func(event *beat.Event) {