Logstash stuck?
Posted: Wed Jul 29, 2015 10:30 am
Reviewing the Log server cluster this morning and realized the one of the nodes was no longer receiving from our firewall. I restarted the logstash service and seems like they are now coming back in. Review of the logstash logs did not indicated any errors, actually there wasn't much events at all.
So I have two questions:
1. Are there any other logging that I can look at to find out what happened?
2. How do I monitoring for this? The alerting component can alert for a threshold reached, can it do alerting when say there are 0 entries for a duration of 1hour?
Thanks.
So I have two questions:
1. Are there any other logging that I can look at to find out what happened?
2. How do I monitoring for this? The alerting component can alert for a threshold reached, can it do alerting when say there are 0 entries for a duration of 1hour?
Thanks.