Hello,
in my working Graylog ist the MongoDB crashed. Now I start with a clean DB and restore a working Backup from February. Unfortunately the log collector does not work, so that filebeat doesent work.
I miss the Direktory /etc/filebeat/ with the filebeat.yml, but before my restore in the Working Area, there wasn’t that Directory likewise.
Has anyone a Idea.
- Ubuntu 20.04
- Graylog 4.1.3
- MongoDB v4.0.25
- Elasticsearch 7.10.2
In one of the filebeat is that log:
2021-08-17T07:42:00.570+0200 INFO instance/beat.go:611 Home path: [/usr/share/filebeat/bin] Config path: [/usr/share/filebeat/bin] Data path: [/var/lib/graylog-sidecar/collectors/filebeat/data] Logs path: [/var/lib/graylog-sidecar/collectors/filebeat/log]
2021-08-17T07:42:00.571+0200 INFO instance/beat.go:618 Beat UUID: 1e30b2fd-023a-4a04-9164-26b405e83244
2021-08-17T07:42:00.571+0200 INFO [seccomp] seccomp/seccomp.go:116 Syscall filter successfully installed
2021-08-17T07:42:00.571+0200 INFO [beat] instance/beat.go:931 Beat info {“system_info”: {“beat”: {“path”: {“config”: “/usr/share/filebeat/bin”, “data”: “/var/lib/graylog-sidecar/collectors/filebeat/data”, “home”: “/usr/share/filebeat/bin”, “logs”: “/var/lib/graylog-sidecar/collectors/filebeat/log”}, “type”: “filebeat”, “uuid”: “1e30b2fd-023a-4a04-9164-26b405e83244”}}}
2021-08-17T07:42:00.571+0200 INFO [beat] instance/beat.go:940 Build info {“system_info”: {“build”: {“commit”: “5cd281153df1eb5e95a4a31994a7846d2c9493e8”, “libbeat”: “6.8.14”, “time”: “2021-02-02T18:46:23.000Z”, “version”: “6.8.14”}}}
2021-08-17T07:42:00.571+0200 INFO [beat] instance/beat.go:943 Go runtime info {“system_info”: {“go”: {“os”:“linux”,“arch”:“amd64”,“max_procs”:8,“version”:“go1.10.8”}}}
2021-08-17T07:42:00.572+0200 INFO [beat] instance/beat.go:947 Host info {“system_info”: {“host”: {“architecture”:“x86_64”,“boot_time”:“2021-08-16T12:10:28+02:00”,“containerized”:false,“name”:“kvit-graylog”,“ip”:[“127.0.0.1/8”,"::1/128",“172.22.23.239/24”,“fe80::a846:96ff:fe9d:d870/64”],“kernel_version”:“5.4.0-80-generic”,“mac”:[“aa:46:96:9d:d8:70”],“os”:{“family”:“debian”,“platform”:“ubuntu”,“name”:“Ubuntu”,“version”:“20.04.2 LTS (Focal Fossa)”,“major”:20,“minor”:4,“patch”:2,“codename”:“focal”},“timezone”:“CEST”,“timezone_offset_sec”:7200,“id”:“83cd4f68db0a403f8c24289cd8790e0b”}}}
2021-08-17T07:42:00.572+0200 INFO [beat] instance/beat.go:976 Process info {“system_info”: {“process”: {“capabilities”: {“inheritable”:null,“permitted”:[“chown”,“dac_override”,“dac_read_search”,“fowner”,“fsetid”,“kill”,“setgid”,“setuid”,“setpcap”,“linux_immutable”,“net_bind_service”,“net_broadcast”,“net_admin”,“net_raw”,“ipc_lock”,“ipc_owner”,“sys_module”,“sys_rawio”,“sys_chroot”,“sys_ptrace”,“sys_pacct”,“sys_admin”,“sys_boot”,“sys_nice”,“sys_resource”,“sys_time”,“sys_tty_config”,“mknod”,“lease”,“audit_write”,“audit_control”,“setfcap”,“mac_override”,“mac_admin”,“syslog”,“wake_alarm”,“block_suspend”,“audit_read”],“effective”:[“chown”,“dac_override”,“dac_read_search”,“fowner”,“fsetid”,“kill”,“setgid”,“setuid”,“setpcap”,“linux_immutable”,“net_bind_service”,“net_broadcast”,“net_admin”,“net_raw”,“ipc_lock”,“ipc_owner”,“sys_module”,“sys_rawio”,“sys_chroot”,“sys_ptrace”,“sys_pacct”,“sys_admin”,“sys_boot”,“sys_nice”,“sys_resource”,“sys_time”,“sys_tty_config”,“mknod”,“lease”,“audit_write”,“audit_control”,“setfcap”,“mac_override”,“mac_admin”,“syslog”,“wake_alarm”,“block_suspend”,“audit_read”],“bounding”:[“chown”,“dac_override”,“dac_read_search”,“fowner”,“fsetid”,“kill”,“setgid”,“setuid”,“setpcap”,“linux_immutable”,“net_bind_service”,“net_broadcast”,“net_admin”,“net_raw”,“ipc_lock”,“ipc_owner”,“sys_module”,“sys_rawio”,“sys_chroot”,“sys_ptrace”,“sys_pacct”,“sys_admin”,“sys_boot”,“sys_nice”,“sys_resource”,“sys_time”,“sys_tty_config”,“mknod”,“lease”,“audit_write”,“audit_control”,“setfcap”,“mac_override”,“mac_admin”,“syslog”,“wake_alarm”,“block_suspend”,“audit_read”],“ambient”:null}, “cwd”: “/”, “exe”: “/usr/share/filebeat/bin/filebeat”, “name”: “filebeat”, “pid”: 4306, “ppid”: 753, “seccomp”: {“mode”:“filter”,“no_new_privs”:true}, “start_time”: “2021-08-17T07:41:59.899+0200”}}}
2021-08-17T07:42:00.572+0200 INFO instance/beat.go:280 Setup Beat: filebeat; Version: 6.8.14
2021-08-17T07:42:00.572+0200 INFO [publisher] pipeline/module.go:110 Beat name: kvit-graylog
2021-08-17T07:42:00.572+0200 ERROR fileset/modules.go:118 Not loading modules. Module directory not found: /usr/share/filebeat/bin/module
2021-08-17T07:42:00.572+0200 INFO [monitoring] log/log.go:117 Starting metrics logging every 30s
2021-08-17T07:42:00.572+0200 INFO instance/beat.go:402 filebeat start running.
2021-08-17T07:42:00.572+0200 INFO registrar/registrar.go:134 Loading registrar data from /var/lib/graylog-sidecar/collectors/filebeat/data/registry
2021-08-17T07:42:00.574+0200 INFO [monitoring] log/log.go:152 Total non-zero metrics {“monitoring”: {“metrics”: {“beat”:{“cpu”:{“system”:{“ticks”:0,“time”:{“ms”:5}},“total”:{“ticks”:10,“time”:{“ms”:16},“value”:10},“user”:{“ticks”:10,“time”:{“ms”:11}}},“handles”:{“limit”:{“hard”:524288,“soft”:1024},“open”:6},“info”:{“ephemeral_id”:“6358755f-40b0-4e8d-a331-bd242bb39079”,“uptime”:{“ms”:8}},“memstats”:{“gc_next”:4194304,“memory_alloc”:2412080,“memory_total”:3867864,“rss”:23019520}},“filebeat”:{“harvester”:{“open_files”:0,“running”:0}},“libbeat”:{“config”:{“module”:{“running”:0}},“output”:{“type”:“logstash”},“pipeline”:{“clients”:0,“events”:{“active”:0}}},“registrar”:{“states”:{“current”:0}},“system”:{“cpu”:{“cores”:8},“load”:{“1”:0.01,“15”:0,“5”:0.01,“norm”:{“1”:0.0013,“15”:0,“5”:0.0013}}}}}}
2021-08-17T07:42:00.574+0200 INFO [monitoring] log/log.go:153 Uptime: 9.594923ms
2021-08-17T07:42:00.574+0200 INFO [monitoring] log/log.go:130 Stopping metrics logging.
2021-08-17T07:42:00.574+0200 INFO instance/beat.go:412 filebeat stopped.
2021-08-17T07:42:00.575+0200 ERROR instance/beat.go:906 Exiting: Could not start registrar: Error loading state: Error decoding states: EOF
Now I get after creating a Symlink /usr/share/filebeat/bin/module of /usr/share/filebeat/module/
2021-08-17T10:48:57.473+0200 INFO instance/beat.go:611 Home path: [/usr/share/filebeat/bin] Config path: [/usr/share/filebeat/bin] Data path: [/var/lib/graylog-sidecar/collectors/filebeat/data] Logs path: [/var/lib/graylog-sidecar/collectors/filebeat/log]
2021-08-17T10:48:57.474+0200 INFO instance/beat.go:618 Beat UUID: 1e30b2fd-023a-4a04-9164-26b405e83244
2021-08-17T10:48:57.474+0200 INFO [seccomp] seccomp/seccomp.go:116 Syscall filter successfully installed
2021-08-17T10:48:57.474+0200 INFO [beat] instance/beat.go:931 Beat info {“system_info”: {“beat”: {“path”: {“config”: “/usr/share/filebeat/bin”, “data”: “/var/lib/graylog-sidecar/collectors/filebeat/data”, “home”: “/usr/share/filebeat/bin”, “logs”: “/var/lib/graylog-sidecar/collectors/filebeat/log”}, “type”: “filebeat”, “uuid”: “1e30b2fd-023a-4a04-9164-26b405e83244”}}}
2021-08-17T10:48:57.474+0200 INFO [beat] instance/beat.go:940 Build info {“system_info”: {“build”: {“commit”: “5cd281153df1eb5e95a4a31994a7846d2c9493e8”, “libbeat”: “6.8.14”, “time”: “2021-02-02T18:46:23.000Z”, “version”: “6.8.14”}}}
2021-08-17T10:48:57.474+0200 INFO [beat] instance/beat.go:943 Go runtime info {“system_info”: {“go”: {“os”:“linux”,“arch”:“amd64”,“max_procs”:8,“version”:“go1.10.8”}}}
2021-08-17T10:48:57.475+0200 INFO [beat] instance/beat.go:947 Host info {“system_info”: {“host”: {“architecture”:“x86_64”,“boot_time”:“2021-08-17T10:48:26+02:00”,“containerized”:false,“name”:“kvit-graylog”,“ip”:[“127.0.0.1/8”,"::1/128",“172.22.23.239/24”,“fe80::a846:96ff:fe9d:d870/64”],“kernel_version”:“5.4.0-80-generic”,“mac”:[“aa:46:96:9d:d8:70”],“os”:{“family”:“debian”,“platform”:“ubuntu”,“name”:“Ubuntu”,“version”:“20.04.2 LTS (Focal Fossa)”,“major”:20,“minor”:4,“patch”:2,“codename”:“focal”},“timezone”:“CEST”,“timezone_offset_sec”:7200,“id”:“83cd4f68db0a403f8c24289cd8790e0b”}}}
2021-08-17T10:48:57.475+0200 INFO [beat] instance/beat.go:976 Process info {“system_info”: {“process”: {“capabilities”: {“inheritable”:null,“permitted”:[“chown”,“dac_override”,“dac_read_search”,“fowner”,“fsetid”,“kill”,“setgid”,“setuid”,“setpcap”,“linux_immutable”,“net_bind_service”,“net_broadcast”,“net_admin”,“net_raw”,“ipc_lock”,“ipc_owner”,“sys_module”,“sys_rawio”,“sys_chroot”,“sys_ptrace”,“sys_pacct”,“sys_admin”,“sys_boot”,“sys_nice”,“sys_resource”,“sys_time”,“sys_tty_config”,“mknod”,“lease”,“audit_write”,“audit_control”,“setfcap”,“mac_override”,“mac_admin”,“syslog”,“wake_alarm”,“block_suspend”,“audit_read”],“effective”:[“chown”,“dac_override”,“dac_read_search”,“fowner”,“fsetid”,“kill”,“setgid”,“setuid”,“setpcap”,“linux_immutable”,“net_bind_service”,“net_broadcast”,“net_admin”,“net_raw”,“ipc_lock”,“ipc_owner”,“sys_module”,“sys_rawio”,“sys_chroot”,“sys_ptrace”,“sys_pacct”,“sys_admin”,“sys_boot”,“sys_nice”,“sys_resource”,“sys_time”,“sys_tty_config”,“mknod”,“lease”,“audit_write”,“audit_control”,“setfcap”,“mac_override”,“mac_admin”,“syslog”,“wake_alarm”,“block_suspend”,“audit_read”],“bounding”:[“chown”,“dac_override”,“dac_read_search”,“fowner”,“fsetid”,“kill”,“setgid”,“setuid”,“setpcap”,“linux_immutable”,“net_bind_service”,“net_broadcast”,“net_admin”,“net_raw”,“ipc_lock”,“ipc_owner”,“sys_module”,“sys_rawio”,“sys_chroot”,“sys_ptrace”,“sys_pacct”,“sys_admin”,“sys_boot”,“sys_nice”,“sys_resource”,“sys_time”,“sys_tty_config”,“mknod”,“lease”,“audit_write”,“audit_control”,“setfcap”,“mac_override”,“mac_admin”,“syslog”,“wake_alarm”,“block_suspend”,“audit_read”],“ambient”:null}, “cwd”: “/”, “exe”: “/usr/share/filebeat/bin/filebeat”, “name”: “filebeat”, “pid”: 1763, “ppid”: 763, “seccomp”: {“mode”:“filter”,“no_new_privs”:true}, “start_time”: “2021-08-17T10:48:56.980+0200”}}}
2021-08-17T10:48:57.475+0200 INFO instance/beat.go:280 Setup Beat: filebeat; Version: 6.8.14
2021-08-17T10:48:57.476+0200 INFO [publisher] pipeline/module.go:110 Beat name: kvit-graylog
2021-08-17T10:48:57.476+0200 INFO [monitoring] log/log.go:117 Starting metrics logging every 30s
2021-08-17T10:48:57.476+0200 INFO instance/beat.go:402 filebeat start running.
2021-08-17T10:48:57.476+0200 INFO registrar/registrar.go:134 Loading registrar data from /var/lib/graylog-sidecar/collectors/filebeat/data/registry
2021-08-17T10:48:57.477+0200 INFO [monitoring] log/log.go:152 Total non-zero metrics {“monitoring”: {“metrics”: {“beat”:{“cpu”:{“system”:{“ticks”:0,“time”:{“ms”:5}},“total”:{“ticks”:10,“time”:{“ms”:16},“value”:10},“user”:{“ticks”:10,“time”:{“ms”:11}}},“handles”:{“limit”:{“hard”:524288,“soft”:1024},“open”:6},“info”:{“ephemeral_id”:“6e659230-8846-4578-b5f7-bbfdebffe36f”,“uptime”:{“ms”:9}},“memstats”:{“gc_next”:4194304,“memory_alloc”:2355552,“memory_total”:3892432,“rss”:22208512}},“filebeat”:{“harvester”:{“open_files”:0,“running”:0}},“libbeat”:{“config”:{“module”:{“running”:0}},“output”:{“type”:“logstash”},“pipeline”:{“clients”:0,“events”:{“active”:0}}},“registrar”:{“states”:{“current”:0}},“system”:{“cpu”:{“cores”:8},“load”:{“1”:0.75,“15”:0.06,“5”:0.19,“norm”:{“1”:0.0938,“15”:0.0075,“5”:0.0238}}}}}}
2021-08-17T10:48:57.478+0200 INFO [monitoring] log/log.go:153 Uptime: 10.323724ms
2021-08-17T10:48:57.478+0200 INFO [monitoring] log/log.go:130 Stopping metrics logging.
2021-08-17T10:48:57.478+0200 INFO instance/beat.go:412 filebeat stopped.
2021-08-17T10:48:57.478+0200 ERROR instance/beat.go:906 Exiting: Could not start registrar: Error loading state: Error decoding states: EOF
Is there someone who can help me and had any idea?