grok parsefalure

This support forum board is for support questions relating to Nagios Log Server, our solution for managing and monitoring critical log data.
User avatar
WillemDH
Posts: 2320
Joined: Wed Mar 20, 2013 5:49 am
Location: Ghent
Contact:

Re: grok parsefalure

Post by WillemDH »

Hey Jesse,

The remove_tag command did work. :) I guess this is ok for me. Could you just have a look at my question earlier in this thread concerning the timestamp being one hour off?

Grtz
Nagios XI 5.8.1
https://outsideit.net
jolson
Attack Rabbit
Posts: 2560
Joined: Thu Feb 12, 2015 12:40 pm

Re: grok parsefalure

Post by jolson »

Please run the following, using your appropriate timezone after the '-z' argument:

Code: Select all

/usr/local/nagioslogserver/scripts/change_timezone.sh -z America/Example
This will set an appropriate time for the logstash Daemon - let me know if this helps to fix your issue. Thanks Willem!
Twits Blog
Show me a man who lives alone and has a perpetually clean kitchen, and 8 times out of 9 I'll show you a man with detestable spiritual qualities.
User avatar
WillemDH
Posts: 2320
Joined: Wed Mar 20, 2013 5:49 am
Location: Ghent
Contact:

Re: grok parsefalure

Post by WillemDH »

Jesse,

Done. I'll see if it helps and let you know.

Grtz
Nagios XI 5.8.1
https://outsideit.net
jolson
Attack Rabbit
Posts: 2560
Joined: Thu Feb 12, 2015 12:40 pm

Re: grok parsefalure

Post by jolson »

Sounds great, thanks Willem.
Twits Blog
Show me a man who lives alone and has a perpetually clean kitchen, and 8 times out of 9 I'll show you a man with detestable spiritual qualities.
User avatar
WillemDH
Posts: 2320
Joined: Wed Mar 20, 2013 5:49 am
Location: Ghent
Contact:

Re: grok parsefalure

Post by WillemDH »

Jesse,

Seem I still have some one hour off timestamps.. Check screenshot:

The strange thing it that it's only wrong in the expanded detail @timestamp

A bug?

Grtz

Willem
You do not have the required permissions to view the files attached to this post.
Nagios XI 5.8.1
https://outsideit.net
scottwilkerson
DevOps Engineer
Posts: 19396
Joined: Tue Nov 15, 2011 3:11 pm
Location: Nagios Enterprises
Contact:

Re: grok parsefalure

Post by scottwilkerson »

The expanded @timestamp is showing the time ending in Z which is GMT and +1 hour from your actual timezone.
Former Nagios employee
Creator:
Human Design Website
Get Your Human Design Chart
User avatar
WillemDH
Posts: 2320
Joined: Wed Mar 20, 2013 5:49 am
Location: Ghent
Contact:

Re: grok parsefalure

Post by WillemDH »

Ah Sry I didn't knew that. So whenever I see a timestamp with trailing Z, this is always in GMT + 1?

Grtz

Willem
Nagios XI 5.8.1
https://outsideit.net
jolson
Attack Rabbit
Posts: 2560
Joined: Thu Feb 12, 2015 12:40 pm

Re: grok parsefalure

Post by jolson »

'Z' stands for Zulu time, which is also GMT and UTC. This means that if you see a trailing 'Z', the time will always match GMT.
Twits Blog
Show me a man who lives alone and has a perpetually clean kitchen, and 8 times out of 9 I'll show you a man with detestable spiritual qualities.
User avatar
WillemDH
Posts: 2320
Joined: Wed Mar 20, 2013 5:49 am
Location: Ghent
Contact:

Re: grok parsefalure

Post by WillemDH »

ok, thanks for the info. This thread can be closed. :)
Nagios XI 5.8.1
https://outsideit.net
jolson
Attack Rabbit
Posts: 2560
Joined: Thu Feb 12, 2015 12:40 pm

Re: grok parsefalure

Post by jolson »

Great - thanks Willem! :)
Twits Blog
Show me a man who lives alone and has a perpetually clean kitchen, and 8 times out of 9 I'll show you a man with detestable spiritual qualities.
Locked