Comments (8)
Unfortunately, host is special because it is actually stored as an integer, not
a string, and doesn't show up in the message. When you search for the IP
listed without the "host:" prefix, ELSA has to interpret it as a literal
string, which won't match the integer representation in the host field. I
attempted a possible fix which would be to always search for both the IP and
its integer representation, but that introduced other inconsistencies and
unexpected search results. I may look at this again, but right now I don't see
a good way of fixing this.
Original comment by [email protected]
on 25 Jul 2012 at 5:24
- Changed state: WontFix
from enterprise-log-search-and-archive.
Sorry, that was actually a copy and paste error. Host *is* in the second query,
just like the first. The only difference is that I add a zero to the limit
argument and then I get zero results.
Original comment by [email protected]
on 25 Jul 2012 at 7:15
from enterprise-log-search-and-archive.
Ah, that's a very different problem! So you see now debug messages or
otherwise in the log to indicate that it tried to batch?
Original comment by [email protected]
on 25 Jul 2012 at 7:46
- Changed state: New
from enterprise-log-search-and-archive.
Here are the last few lines from the query that failed:
* TRACE [2012/07/25 15:06:15] /usr/local/elsa/web/lib/API.pm (2121)
API::_unlimited_sphinx_query 1338 [undef]
total: 9967, overall_limit: 10000
* TRACE [2012/07/25 15:06:18] /usr/local/elsa/web/lib/API.pm (2143)
API::_unlimited_sphinx_query 1338 [undef]
query got 1000 of 51822 results
* DEBUG [2012/07/25 15:06:18] /usr/local/elsa/web/lib/API.pm (2171)
API::_unlimited_sphinx_query 1338 [undef]
found latest time: 1343155405 Tue Jul 24 13:43:25 2012
* DEBUG [2012/07/25 15:06:18] /usr/local/elsa/web/lib/API.pm (2186)
API::_unlimited_sphinx_query 1338 [undef]
received: 10000 of 757126 with overall limit 10000
* DEBUG [2012/07/25 15:06:18] /usr/local/elsa/web/lib/API.pm (2193)
API::_unlimited_sphinx_query 1338 [undef]
completed unlimited query in 39.5081880092621 with 10000 rows
* INFO [2012/07/25 15:06:19] /usr/local/elsa/web/lib/API.pm (1606) API::query
1338 [undef]
Query 173 returned 0 rows
Here are the last few from the query that succeeds:
* TRACE [2012/07/25 15:08:17] /usr/local/elsa/web/lib/API.pm (1921)
API::__ANON__ 1341 [undef]
node 127.0.0.1 got db rows: 1000
* DEBUG [2012/07/25 15:08:17] /usr/local/elsa/web/lib/API.pm (2097)
API::_sphinx_query 1341 [undef]
completed query in 4.19301795959473 with 1000 rows
* INFO [2012/07/25 15:08:17] /usr/local/elsa/web/lib/API.pm (1606) API::query
1341 [undef]
Query 174 returned 1000 rows
Prior to these entries there is a really big line with a bunch of question
marks and integers, separated by commas.
Original comment by [email protected]
on 25 Jul 2012 at 8:09
from enterprise-log-search-and-archive.
Ok, that's good, it did finish:
completed unlimited query in 39.5081880092621 with 10000 rows
So, there should be a CSV file somewhere (it's supposed to email you with those
results) created in the bulk_dir (/tmp by default).
Original comment by [email protected]
on 25 Jul 2012 at 8:50
from enterprise-log-search-and-archive.
I don't see any *.csv files in /tmp, but there are a lot of files with names
that look like MD5 checksums. Are those what I am looking for?
Original comment by [email protected]
on 25 Jul 2012 at 11:06
from enterprise-log-search-and-archive.
The MD5 files are session stores and are unrelated. And I was mistaken, the
files are .json, not .csv. Are there any .json files?
Original comment by [email protected]
on 26 Jul 2012 at 1:33
from enterprise-log-search-and-archive.
Closing due to inactivity.
Original comment by [email protected]
on 29 Nov 2012 at 10:35
- Changed state: Done
from enterprise-log-search-and-archive.
Related Issues (20)
- Internal Server Error [500] with Dashboard
- line "1node(s) with ... logs..." doesn't update and offline dahsboards HOT 1
- node update failure HOT 5
- Parsing is not successful on the web interface HOT 1
- Installer fails on FreeBSD - can provide a patch unless the project is inactive
- Unable to open elsa dash board from Apache HOT 3
- distribution packaging
- lumberjack support
- Question about UNIQUE KEY for "fields" table
- Log Size Limit Problem HOT 1
- Parser for BIND queries not classifying/parsing data from udp(); or log file (custom class and fields)
- The date of the "From" field is locked in a day and not advance. HOT 1
- Trouble installing ELSA correctly HOT 1
- Email Alerts not working - Send to connector opens about:blank window containing log data
- Unable to view stats HOT 1
- Results options after search not working
- Query Log not working
- has Transform is Broken
- Missing Archive. Index not buffering
- Include_data doesnt include data on email
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from enterprise-log-search-and-archive.