Search found 23 matches

by cpatterson1
Thu Dec 15, 2016 3:43 pm
Forum: Nagios Log Server
Topic: Using Filters for problematic log
Replies: 5
Views: 350

Re: Using Filters for problematic log

Great, thanks for you assistance! That is working how I wanted.
by cpatterson1
Thu Dec 15, 2016 10:38 am
Forum: Nagios Log Server
Topic: Using Filters for problematic log
Replies: 5
Views: 350

Re: Using Filters for problematic log

<7> CEF:1|A10|TH3030S|2.7.2-P7-SP3|WAF|Dec 13 2016 14:25:00|session-id|2|src=10.2.52.252 spt=25049 dst=10.2.208.150 dpt=80 hst="changedev.agoc.com" cs1=?dev?DefaultWebServer cs2=fb76283ae9c71b37 act=learn md=passive svc=http req="GET /images/grid/last.gif HTTP/1.1" 0 msg="Ne...
by cpatterson1
Thu Dec 15, 2016 8:51 am
Forum: Nagios Log Server
Topic: Using Filters for problematic log
Replies: 5
Views: 350

Using Filters for problematic log

I am trying to create a grok filter that works for a log we are trying to pull into our system. Issue 1: The issue is the logfile outputs logs like this "Data1|Data2|Data3|" which prevents us from grabbing a couple pieces of information. So, I followed the instructions here to try and repl...
by cpatterson1
Thu Jun 16, 2016 10:44 am
Forum: Nagios Log Server
Topic: nxlog memory leak?
Replies: 1
Views: 522

nxlog memory leak?

Moderator Edit: This thread has been split from another - https://support.nagios.com/forum/viewtopic.php?f=37&t=36623 In the future, please create a new thread and link to the old one instead of adding on. I am seeing a potential memory leak issue and have found it to be related to this non-def...
by cpatterson1
Wed Jun 15, 2016 7:18 am
Forum: Nagios Log Server
Topic: Input type is getting Grokked even when the filter is off
Replies: 12
Views: 1625

Re: Input type is getting Grokked even when the filter is of

Sorry, I was out of office for a few days. However, this isn't resolved as of yet. We're just not seeing the logstash.log get flooded at this point (though it still is getting some hits, we will worry about that at another time). We are still having issues described in the title of this post. Our in...
by cpatterson1
Thu Jun 09, 2016 6:44 am
Forum: Nagios Log Server
Topic: Input type is getting Grokked even when the filter is off
Replies: 12
Views: 1625

Re: Input type is getting Grokked even when the filter is of

Alright, I put this change in place for all of the syslog types we had. This appears to have fixed the log issue as I have not seen a log come in for about 10-15 minutes to that file now and we're getting those log types. So, it appears we're not getting any errors at this point, at least not at a l...
by cpatterson1
Wed Jun 08, 2016 7:38 am
Forum: Nagios Log Server
Topic: Input type is getting Grokked even when the filter is off
Replies: 12
Views: 1625

Re: Input type is getting Grokked even when the filter is of

Again, sorry for the slow response. I pulled a snippet of what is going through the log and I am not necessarily seeing anything indicating errors within Logstash.log (the only thing containing "errors" are the logs it is pulling in that are errors on the remote devices). But it is far fro...
by cpatterson1
Tue Jun 07, 2016 6:47 am
Forum: Nagios Log Server
Topic: Input type is getting Grokked even when the filter is off
Replies: 12
Views: 1625

Re: Input type is getting Grokked even when the filter is of

Sorry for the delay. Obviously I see a lot coming through in the logs, but I do not see any of the type IIS_Requests in that log.
by cpatterson1
Mon Jun 06, 2016 11:34 am
Forum: Nagios Log Server
Topic: Input type is getting Grokked even when the filter is off
Replies: 12
Views: 1625

Re: Input type is getting Grokked even when the filter is of

They should be posted just above your comment (thought to do that after I submitted).
by cpatterson1
Mon Jun 06, 2016 11:30 am
Forum: Nagios Log Server
Topic: Input type is getting Grokked even when the filter is off
Replies: 12
Views: 1625

Re: Input type is getting Grokked even when the filter is of

Below are the Input and Filter we are using (based on this: https://exchange.nagios.org/directory/Addons/Nagios-Log-Server/Dashboards/IIS-Dashboard/details) Here is the Input: tcp { type => 'IIS_requests' tags => 'IIS_requests' port => 5142 codec => json } And here is the filter: if [type] == 'IIS_r...