Logstash Detection of Log Events Issue

Description

I have attacted the conf, sincedb, and log file. The event parsing is not working. If the input log file has only one event, it does not get detected. If the input log has mulitple events, the event next to the last is being parsed twice (even though is was already parsed previosuly) in addition to the last event.

Please explain how is the parsing suppose to work and what can I do to prevent these unwanted actions.

Activity

Show:
Frezer Kifle
January 13, 2014, 9:36 PM

MAYDAY- Please help out anyone. How come start_position does not work as expected? Please someone have mercy and help out here?

Frezer Kifle
January 13, 2014, 9:39 PM

Please help me out, sir. I need to get some answers by today COB. Thanks.

Frezer Kifle
January 14, 2014, 2:59 PM
Edited

There appears to be an issue with start_position and any help would be most helpful.

Richard Pijnenburg
January 14, 2014, 3:26 PM

Hi,

I had a quick look at your issue and your configs.
The first issue i find is that you specify your multiline pattern as "%{LOGLEVEL} +%{TIMESTAMP_ISO8601}" while the first line contains much more then that.
Could you try it out with "%{LOGLEVEL} +%{TIMESTAMP_ISO8601} %{GREEDYDATA}" ?
The greedydata pattern should match anything behind the timestamp.

Cheers.

Jason Kendall
March 6, 2014, 3:02 PM

Can OP please comment?

Assignee

Jordan Sissel

Reporter

Frezer Kifle

Labels

Affects versions

Configure