You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This means that the configured filter works on the first logstash run, but restarting logstash causes the plugin to read in all journald entries, not only the filtered entries.
Version: logstash 6.0.0
Operating System: Docker docker.elastic.co/logstash/logstash image on RHEL 7
Config File (if you have sensitive info, please remove it):
$ docker run --rm --log-driver journald busybox echo test
test
Steps to Reproduce:
Run logstash with the sample config, and use docker run --log-driver journald ... to generate a test entry. Observe that only the docker container output is shown in the logstash stdout output.
Restart logstash, and observe that the logstash stdout output now includes all journald events.
Stop logstash, use rm /tmp/logstash-test/.sincedb_journal to clear the sincedb. Restart logstash, and observe that only the Docker container output is visible again.
The text was updated successfully, but these errors were encountered:
stoallan
added a commit
to stoallan/logstash-input-journald
that referenced
this issue
May 17, 2022
The configured
filter => { ... }
only gets applied if there is not cursor stored in the sincedb:logstash-input-journald/lib/logstash/inputs/journald.rb
Line 119 in 723d2f7
This means that the configured filter works on the first logstash run, but restarting logstash causes the plugin to read in all journald entries, not only the filtered entries.
docker.elastic.co/logstash/logstash
image on RHEL 7Run logstash with the sample config, and use
docker run --log-driver journald ...
to generate a test entry. Observe that only the docker container output is shown in the logstash stdout output.Restart logstash, and observe that the logstash stdout output now includes all journald events.
Stop logstash, use
rm /tmp/logstash-test/.sincedb_journal
to clear the sincedb. Restart logstash, and observe that only the Docker container output is visible again.The text was updated successfully, but these errors were encountered: