A Journey of a Thousand Miles Begins with a Single Step

Resolve multiline grokparsefailure with regex

On a daily logrotate I have noticed that one of my monitored applications is doing a multiline input, but due to a misconfiguration in logstash, the grokparsefailure appears. I just want to leave the message as it is. Therefore logstash provides event dependent configuration capabilities with regular expression comparisons.

Read more

testdisk saved my data from a sd-card

TestDisk is free data recovery software. I got serious problems with my 16 GB SDXC card. It was formatted with ext3 and the superblock was corrupt.

Read more

Replace NaN values with zero

In logstash some grokked fields in messages, that suppose to be numeric, flying in with “NaN” (Not a Number). You can convert them with the mutate filter plugin.

Read more

Debug filebeat

Starting with filebeat can be troublesome, if a misconfiguration exists or he is not sending the logs to logstash or elasticsearch. To analyze that start filebeat in debug mode filebeat -e -v -d '*'.

Read more

Retrieve process id from ps

Example process without the grep command

Read more

Show process tree of a dedicated process

I always wonder if I could display the a certain process with pstree and not the whole process tree itself. It is possible. See below the results after reading the man page and trying out the options.

Read more