Last modified: 2014-02-03 22:56:43 UTC
It appears that no events of the "apache2" type have been stored in logstash since 2014-01-31T23:59:59.000Z. These events are used to drive the fatalmonitor dashboard. I tried restarting the logstash instance on logstash1001 but this did not seem to restore the event stream. Events of other types are being recorded which are delivered via the udp2log transport stream. fluorine.eqiad.wmnet is still adding new lines to /a/mw-log/apache2.log.
The root cause seems to be a bad grok parse pattern. See https://gerrit.wikimedia.org/r/#/c/110971 for a fix that matches config that I have manually deployed on logstash1001.
https://gerrit.wikimedia.org/r/110971 has now been merged. Is this bug resolved/fixed?
I forced a puppet run after the merge and was able to verify the fix.