Skip to content

Instantly share code, notes, and snippets.

@Misirlou
Last active February 25, 2019 17:58
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save Misirlou/c63d4bc948f76ef44c22837a2cf9d4f8 to your computer and use it in GitHub Desktop.
Save Misirlou/c63d4bc948f76ef44c22837a2cf9d4f8 to your computer and use it in GitHub Desktop.
2019-02-25T17:55:28.527Z INFO instance/beat.go:616 Home path: [/usr/share/journalbeat] Config path: [/etc/journalbeat] Data path: [/var/lib/journalbeat] Logs path: [/var/log/journalbeat]
2019-02-25T17:55:28.527Z DEBUG [beat] instance/beat.go:653 Beat metadata path: /var/lib/journalbeat/meta.json
2019-02-25T17:55:28.527Z INFO instance/beat.go:623 Beat UUID: eeaa8133-15e1-4982-9c86-e89d22dc127e
2019-02-25T17:55:28.527Z DEBUG [seccomp] seccomp/seccomp.go:109 Loading syscall filter {"seccomp_filter": {"no_new_privs":true,"flag":"tsync","policy":{"default_action":"errno","syscalls":[{"names":["accept","accept4","access","arch_prctl","bind","brk","clock_gettime","clone","close","connect","dup","dup2","epoll_create","epoll_create1","epoll_ctl","epoll_pwait","epoll_wait","exit","exit_group","fchdir","fchmod","fchown","fcntl","fdatasync","flock","fstat","fsync","ftruncate","futex","getcwd","getdents","getdents64","geteuid","getgid","getpeername","getpid","getppid","getrandom","getrusage","getsockname","getsockopt","gettid","gettimeofday","getuid","inotify_add_watch","inotify_init1","inotify_rm_watch","ioctl","kill","listen","lseek","lstat","madvise","mincore","mkdirat","mmap","mprotect","munmap","nanosleep","newfstatat","open","openat","pipe","pipe2","poll","pread64","pselect6","pwrite64","read","readlink","readlinkat","recvfrom","recvmmsg","recvmsg","rename","renameat","rt_sigaction","rt_sigprocmask","rt_sigreturn","sched_getaffinity","sched_yield","sendfile","sendmmsg","sendmsg","sendto","set_robust_list","setitimer","setsockopt","shutdown","sigaltstack","socket","stat","statfs","sysinfo","tgkill","time","tkill","uname","unlink","unlinkat","wait4","waitid","write","writev"],"action":"allow"}]}}}
2019-02-25T17:55:28.528Z INFO [seccomp] seccomp/seccomp.go:116 Syscall filter successfully installed
2019-02-25T17:55:28.528Z INFO [beat] instance/beat.go:936 Beat info {"system_info": {"beat": {"path": {"config": "/etc/journalbeat", "data": "/var/lib/journalbeat", "home": "/usr/share/journalbeat", "logs": "/var/log/journalbeat"}, "type": "journalbeat", "uuid": "eeaa8133-15e1-4982-9c86-e89d22dc127e"}}}
2019-02-25T17:55:28.528Z INFO [beat] instance/beat.go:945 Build info {"system_info": {"build": {"commit": "928f5e3f35fe28c1bd73513ff1cc89406eb212a6", "libbeat": "6.6.1", "time": "2019-02-13T16:17:25.000Z", "version": "6.6.1"}}}
2019-02-25T17:55:28.528Z INFO [beat] instance/beat.go:948 Go runtime info {"system_info": {"go": {"os":"linux","arch":"amd64","max_procs":2,"version":"go1.10.8"}}}
2019-02-25T17:55:28.528Z INFO [beat] instance/beat.go:952 Host info {"system_info": {"host": {"architecture":"x86_64","boot_time":"2019-01-30T16:05:47Z","containerized":false,"name":"ip-172-31-0-76","ip":["127.0.0.1/8","::1/128","172.31.0.76/20","fe80::c4:89ff:fe0f:4dec/64"],"kernel_version":"4.15.0-1021-aws","mac":["02:c4:89:0f:4d:ec"],"os":{"family":"debian","platform":"ubuntu","name":"Ubuntu","version":"18.04.1 LTS (Bionic Beaver)","major":18,"minor":4,"patch":1,"codename":"bionic"},"timezone":"UTC","timezone_offset_sec":0,"id":"ec2a4d99bd78836d8e05a29b03d55c84"}}}
2019-02-25T17:55:28.529Z INFO [beat] instance/beat.go:981 Process info {"system_info": {"process": {"capabilities": {"inheritable":null,"permitted":["chown","dac_override","dac_read_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux_immutable","net_bind_service","net_broadcast","net_admin","net_raw","ipc_lock","ipc_owner","sys_module","sys_rawio","sys_chroot","sys_ptrace","sys_pacct","sys_admin","sys_boot","sys_nice","sys_resource","sys_time","sys_tty_config","mknod","lease","audit_write","audit_control","setfcap","mac_override","mac_admin","syslog","wake_alarm","block_suspend","audit_read"],"effective":["chown","dac_override","dac_read_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux_immutable","net_bind_service","net_broadcast","net_admin","net_raw","ipc_lock","ipc_owner","sys_module","sys_rawio","sys_chroot","sys_ptrace","sys_pacct","sys_admin","sys_boot","sys_nice","sys_resource","sys_time","sys_tty_config","mknod","lease","audit_write","audit_control","setfcap","mac_override","mac_admin","syslog","wake_alarm","block_suspend","audit_read"],"bounding":["chown","dac_override","dac_read_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux_immutable","net_bind_service","net_broadcast","net_admin","net_raw","ipc_lock","ipc_owner","sys_module","sys_rawio","sys_chroot","sys_ptrace","sys_pacct","sys_admin","sys_boot","sys_nice","sys_resource","sys_time","sys_tty_config","mknod","lease","audit_write","audit_control","setfcap","mac_override","mac_admin","syslog","wake_alarm","block_suspend","audit_read"],"ambient":null}, "cwd": "/home/ubuntu", "exe": "/usr/share/journalbeat/bin/journalbeat", "name": "journalbeat", "pid": 12254, "ppid": 8919, "seccomp": {"mode":"filter","no_new_privs":true}, "start_time": "2019-02-25T17:55:27.970Z"}}}
2019-02-25T17:55:28.529Z INFO instance/beat.go:281 Setup Beat: journalbeat; Version: 6.6.1
2019-02-25T17:55:28.529Z DEBUG [beat] instance/beat.go:302 Initializing output plugins
2019-02-25T17:55:28.530Z DEBUG [filters] add_cloud_metadata/add_cloud_metadata.go:160add_cloud_metadata: starting to fetch metadata, timeout=3s
2019-02-25T17:55:28.531Z DEBUG [filters] add_cloud_metadata/add_cloud_metadata.go:192add_cloud_metadata: received disposition for gce after 1.23096ms. result=[provider:gce, error=failed with http status code 404, metadata={}]
2019-02-25T17:55:28.533Z DEBUG [filters] add_cloud_metadata/add_cloud_metadata.go:192add_cloud_metadata: received disposition for ec2 after 2.776768ms. result=[provider:ec2, error=<nil>, metadata={"availability_zone":"eu-west-1b","instance_id":"i-08af4e3f34f71abfc","machine_type":"t3.small","provider":"ec2","region":"eu-west-1"}]
2019-02-25T17:55:28.533Z DEBUG [filters] add_cloud_metadata/add_cloud_metadata.go:163add_cloud_metadata: fetchMetadata ran for 2.817956ms
2019-02-25T17:55:28.533Z INFO add_cloud_metadata/add_cloud_metadata.go:323 add_cloud_metadata: hosting provider type detected as ec2, metadata={"availability_zone":"eu-west-1b","instance_id":"i-08af4e3f34f71abfc","machine_type":"t3.small","provider":"ec2","region":"eu-west-1"}
2019-02-25T17:55:28.533Z DEBUG [processors] processors/processor.go:66 Processors: add_host_metadata=[netinfo.enabled=[false], cache.ttl=[5m0s]], add_cloud_metadata={"availability_zone":"eu-west-1b","instance_id":"i-08af4e3f34f71abfc","machine_type":"t3.small","provider":"ec2","region":"eu-west-1"}
2019-02-25T17:55:28.533Z INFO elasticsearch/client.go:165 Elasticsearch url: https://2a07f15a7535487ba2e08c778fe9ea47.eu-west-1.aws.found.io:443
2019-02-25T17:55:28.534Z DEBUG [publish] pipeline/consumer.go:137 start pipeline event consumer
2019-02-25T17:55:28.534Z INFO [publisher] pipeline/module.go:110 Beat name: ip-172-31-0-76
2019-02-25T17:55:28.534Z WARN [cfgwarn] beater/journalbeat.go:49 EXPERIMENTAL: Journalbeat is experimental.
2019-02-25T17:55:28.537Z DEBUG [input] reader/journal.go:86 New local journal is opened for reading {"id": "fc0a3eb1-c364-46bd-8142-4962571320ec", "path": "local"}
2019-02-25T17:55:28.537Z DEBUG [journal] reader/journal.go:130 Added matcher expression: _SYSTEMD_UNIT=consumer_delivery
2019-02-25T17:55:28.537Z DEBUG [input] reader/journal.go:153 Seeking method set to cursor, but no state is saved for reader. Starting to read from the beginning {"id": "fc0a3eb1-c364-46bd-8142-4962571320ec", "path": "local"}
2019-02-25T17:55:28.537Z DEBUG [processors] processors/processor.go:66 Processors:
2019-02-25T17:55:28.537Z DEBUG [input] input/input.go:108 New input is created for paths [] {"id": "fc0a3eb1-c364-46bd-8142-4962571320ec"}
2019-02-25T17:55:28.537Z INFO instance/beat.go:403 journalbeat start running.
2019-02-25T17:55:28.537Z INFO [journalbeat] beater/journalbeat.go:103 journalbeat is running! Hit CTRL-C to stop it.
2019-02-25T17:55:28.538Z INFO [monitoring] log/log.go:117 Starting metrics logging every 30s
2019-02-25T17:55:58.540Z INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":0,"time":{"ms":4}},"total":{"ticks":40,"time":{"ms":44},"value":40},"user":{"ticks":40,"time":{"ms":40}}},"handles":{"limit":{"hard":1048576,"soft":1024},"open":9},"info":{"ephemeral_id":"f2a721be-2df4-428e-829a-0feadafdde1c","uptime":{"ms":30032}},"memstats":{"gc_next":4194304,"memory_alloc":2061328,"memory_total":3960536,"rss":23572480}},"journalbeat":{"journals":{"journal_0":{"path":"LOCAL_SYSTEM_JOURNAL","size_in_bytes":268451840}},"libbeat":{"output":{"type":"elasticsearch"},"pipeline":{"clients":1}},"system":{"cpu":{"cores":2},"load":{"1":0.16,"15":0.1,"5":0.14,"norm":{"1":0.08,"15":0.05,"5":0.07}}}}}}}
2019-02-25T17:56:28.539Z INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":0,"time":{"ms":4}},"total":{"ticks":40,"time":{"ms":6},"value":40},"user":{"ticks":40,"time":{"ms":2}}},"handles":{"limit":{"hard":1048576,"soft":1024},"open":9},"info":{"ephemeral_id":"f2a721be-2df4-428e-829a-0feadafdde1c","uptime":{"ms":60032}},"memstats":{"gc_next":4194304,"memory_alloc":2367896,"memory_total":4267104}},"libbeat":{"config":{"module":{"running":0}},"output":{"type":"elasticsearch"},"pipeline":{"clients":1,"events":{"active":0}}},"system":{"cpu":{"cores":2},"load":{"1":0.1,"15":0.1,"5":0.12,"norm":{"1":0.05,"15":0.05,"5":0.06}}}}}}
2019-02-25T17:56:58.539Z INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":10,"time":{"ms":4}},"total":{"ticks":50,"time":{"ms":5},"value":50},"user":{"ticks":40,"time":{"ms":1}}},"handles":{"limit":{"hard":1048576,"soft":1024},"open":9},"info":{"ephemeral_id":"f2a721be-2df4-428e-829a-0feadafdde1c","uptime":{"ms":90033}},"memstats":{"gc_next":4194304,"memory_alloc":2812344,"memory_total":4711552}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0}}},"system":{"load":{"1":0.06,"15":0.09,"5":0.11,"norm":{"1":0.03,"15":0.045,"5":0.055}}}}}}
2019-02-25T17:57:00.710Z DEBUG [service] service/service.go:50 Received sigterm/sigint, stopping
2019-02-25T17:57:00.710Z DEBUG [publish] pipeline/client.go:148 client: closing acker
2019-02-25T17:57:00.710Z INFO [journalbeat] beater/journalbeat.go:128 journalbeat is stopping
2019-02-25T17:57:00.711Z DEBUG [publish] pipeline/client.go:150 client: done closing acker
2019-02-25T17:57:00.711Z DEBUG [publish] pipeline/client.go:154 client: cancelled 0 events
2019-02-25T17:57:00.711Z INFO [monitoring] log/log.go:152 Total non-zero metrics {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":10,"time":{"ms":13}},"total":{"ticks":50,"time":{"ms":58},"value":50},"user":{"ticks":40,"time":{"ms":45}}},"handles":{"limit":{"hard":1048576,"soft":1024},"open":5},"info":{"ephemeral_id":"f2a721be-2df4-428e-829a-0feadafdde1c","uptime":{"ms":92205}},"memstats":{"gc_next":4194304,"memory_alloc":2924280,"memory_total":4823488,"rss":23572480}},"libbeat":{"config":{"module":{"running":0}},"output":{"type":"elasticsearch"},"pipeline":{"clients":1,"events":{"active":0}}},"system":{"cpu":{"cores":2},"load":{"1":0.06,"15":0.09,"5":0.11,"norm":{"1":0.03,"15":0.045,"5":0.055}}}}}}
2019-02-25T17:57:00.712Z INFO [monitoring] log/log.go:153 Uptime: 1m32.206137739s
2019-02-25T17:57:00.712Z INFO [monitoring] log/log.go:130 Stopping metrics logging.
2019-02-25T17:57:00.712Z INFO instance/beat.go:413 journalbeat stopped.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment