Can you please check if this is an error? This log is very hard to read because there's no line breaks. I see some events from the host IP which seem to be not making into log server interface.
Code: Select all
{:timestamp=>"2016-07-29T12:49:45.717000-0300", :message=>"failed action with response of 400, dropping action: [\"index\", {:_id=>nil, :_index=>\"logstash-2016.07.29\", :_type=>\"syslog\", :_routing=>nil}, #<LogStash::Event:0x7f5eb2dc @metadata={\"retry_count\"=>0}, @accessors=#<LogStash::Util::Accessors:0x31553c71 @store={\"message\"=>\"4D86110000BC: warning: header From: Nagios-xxxxx <[email protected]> from nagios.xxxxx.bc[AAA.BB.CC.DD]; from=<[email protected]> to=<[email protected]> proto=ESMTP helo=<localhost.localdomain>\\n\", \"@version\"=>\"1\", \"@timestamp\"=>\"2016-07-29T15:49:45.000Z\", \"type\"=>\"syslog\", \"host\"=>\"AAA.BB.EE.FF\", \"priority\"=>22, \"timestamp\"=>\"Jul 29 12:49:45\", \"logsource\"=>\"va581\", \"program\"=>\"postfix/cleanup\", \"pid\"=>\"664\", \"severity\"=>6, \"facility\"=>2, \"facility_label\"=>\"mail\", \"severity_label\"=>\"Informational\"}, @lut={\"type\"=>[{\"message\"=>\"4D86110000BC: warning: header From: Nagios-xxxxx <[email protected]> from nagios.xxxxx.bc[AAA.BB.CC.DD]; from=<[email protected]> to=<[email protected]> proto=ESMTP helo=<localhost.localdomain>\\n\", \"@version\"=>\"1\", \"@timestamp\"=>\"2016-07-29T15:49:45.000Z\", \"type\"=>\"syslog\", \"host\"=>\"AAA.BB.EE.FF\", \"priority\"=>22, \"timestamp\"=>\"Jul 29 12:49:45\", \"logsource\"=>\"va581\", \"program\"=>\"postfix/cleanup\", \"pid\"=>\"664\", \"severity\"=>6, \"facility\"=>2, \"facility_label\"=>\"mail\", \"severity_label\"=>\"Informational\"}, \"type\"], \"host\"=>[{\"message\"=>\"4D86110000BC: warning: header From: Nagios-xxxxx <[email protected]> from nagios.xxxxx.bc[AAA.BB.CC.DD]; from=<[email protected]> to=<[email protected]> proto=ESMTP helo=<localhost.localdomain>\\n\", \"@version\"=>\"1\", \"@timestamp\"=>\"2016-07-29T15:49:45.000Z\", \"type\"=>\"syslog\", \"host\"=>\"AAA.BB.EE.FF\", \"priority\"=>22, \"timestamp\"=>\"Jul 29 12:49:45\", \"logsource\"=>\"va581\", \"program\"=>\"postfix/cleanup\", \"pid\"=>\"664\", \"severity\"=>6, \"facility\"=>2, \"facility_label\"=>\"mail\", \"severity_label\"=>\"Informational\"}, \"host\"], \"message\"=>[{\"message\"=>\"4D86110000BC: warning: header From: Nagios-xxxxx <[email protected]> from nagios.xxxxx.bc[AAA.BB.CC.DD]; from=<[email protected]> to=<[email protected]> proto=ESMTP helo=<localhost.localdomain>\\n\", \"@version\"=>\"1\", \"@timestamp\"=>\"2016-07-29T15:49:45.000Z\", \"type\"=>\"syslog\", \"host\"=>\"AAA.BB.EE.FF\", \"priority\"=>22, \"timestamp\"=>\"Jul 29 12:49:45\", \"logsource\"=>\"va581\", \"program\"=>\"postfix/cleanup\", \"pid\"=>\"664\", \"severity\"=>6, \"facility\"=>2, \"facility_label\"=>\"mail\", \"severity_label\"=>\"Informational\"}, \"message\"], \"priority\"=>[{\"message\"=>\"4D86110000BC: warning: header From: Nagios-xxxxx <[email protected]> from nagios.xxxxx.bc[AAA.BB.CC.DD]; from=<[email protected]> to=<[email protected]> proto=ESMTP helo=<localhost.localdomain>\\n\", \"@version\"=>\"1\", \"@timestamp\"=>\"2016-07-29T15:49:45.000Z\", \"type\"=>\"syslog\", \"host\"=>\"AAA.BB.EE.FF\", \"priority\"=>22, \"timestamp\"=>\"Jul 29 12:49:45\", \"logsource\"=>\"va581\", \"program\"=>\"postfix/cleanup\", \"pid\"=>\"664\", \"severity\"=>6, \"facility\"=>2, \"facility_label\"=>\"mail\", \"severity_label\"=>\"Informational\"}, \"priority\"], \"timestamp\"=>[{\"message\"=>\"4D86110000BC: warning: header From: Nagios-xxxxx <[email protected]> from nagios.xxxxx.bc[AAA.BB.CC.DD]; from=<[email protected]> to=<[email protected]> proto=ESMTP helo=<localhost.localdomain>\\n\", \"@version\"=>\"1\", \"@timestamp\"=>\"2016-07-29T15:49:45.000Z\", \"type\"=>\"syslog\", \"host\"=>\"AAA.BB.EE.FF\", \"priority\"=>22, \"timestamp\"=>\"Jul 29 12:49:45\", \"logsource\"=>\"va581\", \"program\"=>\"postfix/cleanup\", \"pid\"=>\"664\", \"severity\"=>6, \"facility\"=>2, \"facility_label\"=>\"mail\", \"severity_label\"=>\"Informational\"}, \"timestamp\"], \"logsource\"=>[{\"message\"=>\"4D86110000BC: warning: header From: Nagios-xxxxx <[email protected]> from nagios.xxxxx.bc[AAA.BB.CC.DD]; from=<[email protected]> to=<[email protected]> proto=ESMTP helo=<localhost.localdomain>\\n\", \"@version\"=>\"1\", \"@timestamp\"=>\"2016-07-29T15:49:45.000Z\", \"type\"=>\"syslog\", \"host\"=>\"AAA.BB.EE.FF\", \"priority\"=>22, \"timestamp\"=>\"Jul 29 12:49:45\", \"logsource\"=>\"va581\", \"program\"=>\"postfix/cleanup\", \"pid\"=>\"664\", \"severity\"=>6, \"facility\"=>2, \"facility_label\"=>\"mail\", \"severity_label\"=>\"Informational\"}, \"logsource\"], \"program\"=>[{\"message\"=>\"4D86110000BC: warning: header From: Nagios-xxxxx <[email protected]> from nagios.xxxxx.bc[AAA.BB.CC.DD]; from=<[email protected]> to=<[email protected]> proto=ESMTP helo=<localhost.localdomain>\\n\", \"@version\"=>\"1\", \"@timestamp\"=>\"2016-07-29T15:49:45.000Z\", \"type\"=>\"syslog\", \"host\"=>\"AAA.BB.EE.FF\", \"priority\"=>22, \"timestamp\"=>\"Jul 29 12:49:45\", \"logsource\"=>\"va581\", \"program\"=>\"postfix/cleanup\", \"pid\"=>\"664\", \"severity\"=>6, \"facility\"=>2, \"facility_label\"=>\"mail\", \"severity_label\"=>\"Informational\"}, \"program\"], \"pid\"=>[{\"message\"=>\"4D86110000BC: warning: header From: Nagios-xxxxx <[email protected]> from nagios.xxxxx.bc[AAA.BB.CC.DD]; from=<[email protected]> to=<[email protected]> proto=ESMTP helo=<localhost.localdomain>\\n\", \"@version\"=>\"1\", \"@timestamp\"=>\"2016-07-29T15:49:45.000Z\", \"type\"=>\"syslog\", \"host\"=>\"AAA.BB.EE.FF\", \"priority\"=>22, \"timestamp\"=>\"Jul 29 12:49:45\", \"logsource\"=>\"va581\", \"program\"=>\"postfix/cleanup\", \"pid\"=>\"664\", \"severity\"=>6, \"facility\"=>2, \"facility_label\"=>\"mail\", \"severity_label\"=>\"Informational\"}, \"pid\"], \"tags\"=>[{\"message\"=>\"4D86110000BC: warning: header From: Nagios-xxxxx <[email protected]> from nagios.xxxxx.bc[AAA.BB.CC.DD]; from=<[email protected]> to=<[email protected]> proto=ESMTP helo=<localhost.localdomain>\\n\", \"@version\"=>\"1\", \"@timestamp\"=>\"2016-07-29T15:49:45.000Z\", \"type\"=>\"syslog\", \"host\"=>\"AAA.BB.EE.FF\", \"priority\"=>22, \"timestamp\"=>\"Jul 29 12:49:45\", \"logsource\"=>\"va581\", \"program\"=>\"postfix/cleanup\", \"pid\"=>\"664\", \"severity\"=>6, \"facility\"=>2, \"facility_label\"=>\"mail\", \"severity_label\"=>\"Informational\"}, \"tags\"], \"severity\"=>[{\"message\"=>\"4D86110000BC: warning: header From: Nagios-xxxxx <[email protected]> from nagios.xxxxx.bc[AAA.BB.CC.DD]; from=<[email protected]> to=<[email protected]> proto=ESMTP helo=<localhost.localdomain>\\n\", \"@version\"=>\"1\", \"@timestamp\"=>\"2016-07-29T15:49:45.000Z\", \"type\"=>\"syslog\", \"host\"=>\"AAA.BB.EE.FF\", \"priority\"=>22, \"timestamp\"=>\"Jul 29 12:49:45\", \"logsource\"=>\"va581\", \"program\"=>\"postfix/cleanup\", \"pid\"=>\"664\", \"severity\"=>6, \"facility\"=>2, \"facility_label\"=>\"mail\", \"severity_label\"=>\"Informational\"}, \"severity\"], \"facility\"=>[{\"message\"=>\"4D86110000BC: warning: header From: Nagios-xxxxx <[email protected]> from nagios.xxxxx.bc[AAA.BB.CC.DD]; from=<[email protected]> to=<[email protected]> proto=ESMTP helo=<localhost.localdomain>\\n\", \"@version\"=>\"1\", \"@timestamp\"=>\"2016-07-29T15:49:45.000Z\", \"type\"=>\"syslog\", \"host\"=>\"AAA.BB.EE.FF\", \"priority\"=>22, \"timestamp\"=>\"Jul 29 12:49:45\", \"logsource\"=>\"va581\", \"program\"=>\"postfix/cleanup\", \"pid\"=>\"664\", \"severity\"=>6, \"facility\"=>2, \"facility_label\"=>\"mail\", \"severity_label\"=>\"Informational\"}, \"facility\"], \"timestamp8601\"=>[{\"message\"=>\"4D86110000BC: warning: header From: Nagios-xxxxx <[email protected]> from nagios.xxxxx.bc[AAA.BB.CC.DD]; from=<[email protected]> to=<[email protected]> proto=ESMTP helo=<localhost.localdomain>\\n\", \"@ve