Skip to content

Instantly share code, notes, and snippets.

@holiiveira
Created June 4, 2019 11:42
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save holiiveira/3ee5b6e97f496ba26ab5d0ec2dd4a428 to your computer and use it in GitHub Desktop.
Save holiiveira/3ee5b6e97f496ba26ab5d0ec2dd4a428 to your computer and use it in GitHub Desktop.
2019-06-04T08:19:49.385-0300 INFO instance/beat.go:571 Home path: [C:\Program Files\Auditbeat] Config path: [C:\Program Files\Auditbeat] Data path: [C:\ProgramData\auditbeat] Logs path: [C:\ProgramData\auditbeat\logs]
2019-06-04T08:19:49.389-0300 INFO instance/beat.go:579 Beat ID: 2fcf4b76-f139-49a9-87e9-5a8c7c32fd65
2019-06-04T08:19:49.389-0300 INFO [index-management.ilm] ilm/ilm.go:129 Policy name: auditbeat-7.1.0
2019-06-04T08:19:49.389-0300 INFO [beat] instance/beat.go:827 Beat info {"system_info": {"beat": {"path": {"config": "C:\\Program Files\\Auditbeat", "data": "C:\\ProgramData\\auditbeat", "home": "C:\\Program Files\\Auditbeat", "logs": "C:\\ProgramData\\auditbeat\\logs"}, "type": "auditbeat", "uuid": "2fcf4b76-f139-49a9-87e9-5a8c7c32fd65"}}}
2019-06-04T08:19:49.390-0300 INFO [beat] instance/beat.go:836 Build info {"system_info": {"build": {"commit": "03b3db2a1d9d76fdf10475e829fce436c61901e4", "libbeat": "7.1.0", "time": "2019-05-15T23:57:38.000Z", "version": "7.1.0"}}}
2019-06-04T08:19:49.390-0300 INFO [beat] instance/beat.go:839 Go runtime info {"system_info": {"go": {"os":"windows","arch":"amd64","max_procs":8,"version":"go1.11.5"}}}
2019-06-04T08:19:49.409-0300 INFO [beat] instance/beat.go:872 Process info {"system_info": {"process": {"cwd": "C:\\Windows\\system32", "exe": "C:\\Program Files\\Auditbeat\\auditbeat.exe", "name": "auditbeat.exe", "pid": 4420, "ppid": 560, "start_time": "2019-06-04T08:19:49.340-0300"}}}
2019-06-04T08:19:49.410-0300 INFO instance/beat.go:280 Setup Beat: auditbeat; Version: 7.1.0
2019-06-04T08:19:49.411-0300 INFO [publisher] pipeline/module.go:97 Beat name: ts04
2019-06-04T08:19:49.427-0300 WARN [cfgwarn] process/process.go:128 BETA: The system/process dataset is beta
2019-06-04T08:19:49.431-0300 WARN [process] process/process.go:165 Running as non-root user, will likely not report all processes.
2019-06-04T08:19:49.431-0300 INFO instance/beat.go:391 auditbeat start running.
2019-06-04T08:19:49.431-0300 INFO [monitoring] log/log.go:117 Starting metrics logging every 30s
2019-06-04T08:20:03.114-0300 INFO pipeline/output.go:95 Connecting to backoff(async(tcp://elk:5007))
2019-06-04T08:20:03.114-0300 INFO pipeline/output.go:105 Connection to backoff(async(tcp://elk:5007)) established
2019-06-04T08:20:19.569-0300 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":109,"time":{"ms":109}},"total":{"ticks":311,"time":{"ms":327},"value":311},"user":{"ticks":202,"time":{"ms":218}}},"handles":{"open":224},"info":{"ephemeral_id":"72eba20b-7f85-4170-968a-e0de90b1f1c7","uptime":{"ms":30104}},"memstats":{"gc_next":6763520,"memory_alloc":3387888,"memory_total":10384456,"rss":24662016}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":2,"batches":2,"total":2},"read":{"bytes":12},"type":"logstash","write":{"bytes":1274}},"pipeline":{"clients":1,"events":{"active":0,"filtered":168,"published":2,"retry":1,"total":170},"queue":{"acked":2}}},"metricbeat":{"system":{"process":{"events":170,"success":170}}},"system":{"cpu":{"cores":8}}}}}
2019-06-04T08:20:49.514-0300 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":156,"time":{"ms":62}},"total":{"ticks":468,"time":{"ms":156},"value":468},"user":{"ticks":312,"time":{"ms":94}}},"handles":{"open":235},"info":{"ephemeral_id":"72eba20b-7f85-4170-968a-e0de90b1f1c7","uptime":{"ms":60113}},"memstats":{"gc_next":6783744,"memory_alloc":5357392,"memory_total":14926960,"rss":2928640}},"libbeat":{"config":{"module":{"running":0}},"output":{"events":{"acked":1,"batches":1,"total":1},"read":{"bytes":6},"write":{"bytes":656}},"pipeline":{"clients":1,"events":{"active":0,"filtered":171,"published":1,"total":172},"queue":{"acked":1}}},"metricbeat":{"system":{"process":{"events":172,"success":172}}}}}}
2019-06-04T08:21:19.550-0300 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":234,"time":{"ms":78}},"total":{"ticks":624,"time":{"ms":156},"value":624},"user":{"ticks":390,"time":{"ms":78}}},"handles":{"open":237},"info":{"ephemeral_id":"72eba20b-7f85-4170-968a-e0de90b1f1c7","uptime":{"ms":90193}},"memstats":{"gc_next":4194304,"memory_alloc":2792528,"memory_total":17876152,"rss":962560}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0,"filtered":168,"total":168}}},"metricbeat":{"system":{"process":{"events":168,"success":168}}}}}}
2019-06-04T08:21:49.545-0300 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":343,"time":{"ms":109}},"total":{"ticks":920,"time":{"ms":296},"value":920},"user":{"ticks":577,"time":{"ms":187}}},"handles":{"open":237},"info":{"ephemeral_id":"72eba20b-7f85-4170-968a-e0de90b1f1c7","uptime":{"ms":120105}},"memstats":{"gc_next":4194304,"memory_alloc":2004504,"memory_total":20881056,"rss":151552}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0,"filtered":171,"total":171}}},"metricbeat":{"system":{"process":{"events":171,"success":171}}}}}}
2019-06-04T08:22:19.553-0300 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":405,"time":{"ms":47}},"total":{"ticks":1153,"time":{"ms":250},"value":1153},"user":{"ticks":748,"time":{"ms":203}}},"handles":{"open":245},"info":{"ephemeral_id":"72eba20b-7f85-4170-968a-e0de90b1f1c7","uptime":{"ms":150195}},"memstats":{"gc_next":4194304,"memory_alloc":3309136,"memory_total":23819184,"rss":147456}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0,"filtered":168,"total":168}}},"metricbeat":{"system":{"process":{"events":168,"success":168}}}}}}
2019-06-04T08:22:49.565-0300 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":436,"time":{"ms":31}},"total":{"ticks":1340,"time":{"ms":171},"value":1340},"user":{"ticks":904,"time":{"ms":140}}},"handles":{"open":247},"info":{"ephemeral_id":"72eba20b-7f85-4170-968a-e0de90b1f1c7","uptime":{"ms":180105}},"memstats":{"gc_next":4194304,"memory_alloc":2613784,"memory_total":26829000,"rss":143360}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0,"filtered":171,"total":171}}},"metricbeat":{"system":{"process":{"events":171,"success":171}}}}}}
2019-06-04T08:23:19.535-0300 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":499,"time":{"ms":78}},"total":{"ticks":1513,"time":{"ms":187},"value":1513},"user":{"ticks":1014,"time":{"ms":109}}},"handles":{"open":245},"info":{"ephemeral_id":"72eba20b-7f85-4170-968a-e0de90b1f1c7","uptime":{"ms":210105}},"memstats":{"gc_next":4194304,"memory_alloc":3588160,"memory_total":29768824,"rss":135168}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0,"filtered":168,"total":168}}},"metricbeat":{"system":{"process":{"events":168,"success":168}}}}}}
2019-06-04T08:23:49.489-0300 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":577,"time":{"ms":63}},"total":{"ticks":1653,"time":{"ms":126},"value":1653},"user":{"ticks":1076,"time":{"ms":63}}},"handles":{"open":248},"info":{"ephemeral_id":"72eba20b-7f85-4170-968a-e0de90b1f1c7","uptime":{"ms":240104}},"memstats":{"gc_next":4194304,"memory_alloc":2622296,"memory_total":32779696,"rss":192512}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0,"filtered":171,"total":171}}},"metricbeat":{"system":{"process":{"events":171,"success":171}}}}}}
2019-06-04T08:24:19.490-0300 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":608,"time":{"ms":47}},"total":{"ticks":1809,"time":{"ms":171},"value":1809},"user":{"ticks":1201,"time":{"ms":124}}},"handles":{"open":248},"info":{"ephemeral_id":"72eba20b-7f85-4170-968a-e0de90b1f1c7","uptime":{"ms":270105}},"memstats":{"gc_next":4194304,"memory_alloc":3673056,"memory_total":35709456,"rss":94208}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0,"filtered":168,"total":168}}},"metricbeat":{"system":{"process":{"events":168,"success":168}}}}}}
2019-06-04T08:24:49.559-0300 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":686,"time":{"ms":62}},"total":{"ticks":1965,"time":{"ms":140},"value":1965},"user":{"ticks":1279,"time":{"ms":78}}},"handles":{"open":251},"info":{"ephemeral_id":"72eba20b-7f85-4170-968a-e0de90b1f1c7","uptime":{"ms":300105}},"memstats":{"gc_next":4194304,"memory_alloc":2659304,"memory_total":38693848,"rss":81920}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0,"filtered":170,"total":170}}},"metricbeat":{"system":{"process":{"events":170,"success":170}}}}}}
2019-06-04T08:25:19.507-0300 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":733,"time":{"ms":47}},"total":{"ticks":2137,"time":{"ms":157},"value":2137},"user":{"ticks":1404,"time":{"ms":110}}},"handles":{"open":252},"info":{"ephemeral_id":"72eba20b-7f85-4170-968a-e0de90b1f1c7","uptime":{"ms":330105}},"memstats":{"gc_next":4194304,"memory_alloc":3750968,"memory_total":41620376,"rss":188416}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0,"filtered":168,"total":168}}},"metricbeat":{"system":{"process":{"events":168,"success":168}}}}}}
2019-06-04T08:25:49.551-0300 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":811,"time":{"ms":78}},"total":{"ticks":2386,"time":{"ms":249},"value":2386},"user":{"ticks":1575,"time":{"ms":171}}},"handles":{"open":252},"info":{"ephemeral_id":"72eba20b-7f85-4170-968a-e0de90b1f1c7","uptime":{"ms":360104}},"memstats":{"gc_next":4194304,"memory_alloc":2957808,"memory_total":44595264,"rss":131072}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0,"filtered":169,"total":169}}},"metricbeat":{"system":{"process":{"events":169,"success":169}}}}}}
2019-06-04T08:26:19.492-0300 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":873,"time":{"ms":62}},"total":{"ticks":2620,"time":{"ms":234},"value":2620},"user":{"ticks":1747,"time":{"ms":172}}},"handles":{"open":252},"info":{"ephemeral_id":"72eba20b-7f85-4170-968a-e0de90b1f1c7","uptime":{"ms":390105}},"memstats":{"gc_next":4194304,"memory_alloc":2195688,"memory_total":47498616,"rss":106496}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0,"filtered":165,"total":165}}},"metricbeat":{"system":{"process":{"events":165,"success":165}}}}}}
2019-06-04T08:26:49.554-0300 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":920,"time":{"ms":47}},"total":{"ticks":2807,"time":{"ms":187},"value":2807},"user":{"ticks":1887,"time":{"ms":140}}},"handles":{"open":252},"info":{"ephemeral_id":"72eba20b-7f85-4170-968a-e0de90b1f1c7","uptime":{"ms":420224}},"memstats":{"gc_next":4194304,"memory_alloc":3409872,"memory_total":50455688,"rss":151552}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0,"filtered":168,"total":168}}},"metricbeat":{"system":{"process":{"events":168,"success":168}}}}}}
2019-06-04T08:27:19.491-0300 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":1014,"time":{"ms":94}},"total":{"ticks":2995,"time":{"ms":203},"value":2995},"user":{"ticks":1981,"time":{"ms":109}}},"handles":{"open":252},"info":{"ephemeral_id":"72eba20b-7f85-4170-968a-e0de90b1f1c7","uptime":{"ms":450105}},"memstats":{"gc_next":4194304,"memory_alloc":2685656,"memory_total":53362336,"rss":90112}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0,"filtered":165,"total":165}}},"metricbeat":{"system":{"process":{"events":165,"success":165}}}}}}
2019-06-04T08:27:49.490-0300 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":1060,"time":{"ms":46}},"total":{"ticks":3166,"time":{"ms":156},"value":3166},"user":{"ticks":2106,"time":{"ms":110}}},"handles":{"open":252},"info":{"ephemeral_id":"72eba20b-7f85-4170-968a-e0de90b1f1c7","uptime":{"ms":480104}},"memstats":{"gc_next":4194304,"memory_alloc":3755792,"memory_total":56320208,"rss":102400}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0,"filtered":168,"total":168}}},"metricbeat":{"system":{"process":{"events":168,"success":168}}}}}}
2019-06-04T08:28:19.492-0300 INFO [monitoring] log/log.go:144 Non-zero metrics in the last 30s {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":1123,"time":{"ms":63}},"total":{"ticks":3244,"time":{"ms":94},"value":3244},"user":{"ticks":2121,"time":{"ms":31}}},"handles":{"open":252},"info":{"ephemeral_id":"72eba20b-7f85-4170-968a-e0de90b1f1c7","uptime":{"ms":510161}},"memstats":{"gc_next":4194304,"memory_alloc":2804256,"memory_total":59219784,"rss":212992}},"libbeat":{"config":{"module":{"running":0}},"pipeline":{"clients":1,"events":{"active":0,"filtered":165,"total":165}}},"metricbeat":{"system":{"process":{"events":165,"success":165}}}}}}
@holiiveira
Copy link
Author

I removed log information: [beat] instance/beat.go:843 Host info

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment