Skip to main content

python daemon that munches on logs and sends their contents to logstash

Installation

Using PIP:

From Github:

pip install git+git://github.com/josegonzalez/beaver.git#egg=beaver

From PyPI:

pip install beaver==1

Usage

usage:

beaver [-h] [-r {worker,interactive}] [-m {bind,connect}] [-p PATH]
                 [-f FILES [FILES ...]] [-t TRANSPORT]

optional arguments:

-h, --help            show this help message and exit
-r {worker,interactive}, --run {worker,interactive}
                      run worker or interactive mode
-m {bind,connect}, --mode {bind,connect}
                      bind or connect mode
-p PATH, --path PATH  path to log files
-f FILES [FILES ...], --files FILES [FILES ...]
                      space-separated filelist to watch. Overrides --path
                      argument
-t {amqp,redis,stdout}, --transport {amqp,redis,stdout}
                  log transport method

Background

Beaver provides an lightweight method for shipping local log files to Logstash. It does this using either redis, stdin, zeromq as the transport. This means you’ll need a redis, stdin, zeromq input somewhere down the road to get the events.

Events are sent in logstash’s json_event format. Options can also be set as environment variables.

Examples

Example 1: Listen to all files in the default path of /var/log on standard out:

beaver

Example 2: Sending logs from /var/log files to a redis list:

REDIS_URL="redis://localhost:6379/0" beaver -t redis

Example 3: Use environment variables to send logs from /var/log files to a redis list:

REDIS_URL="redis://localhost:6379/0" BEAVER_PATH="/var/log" BEAVER_TRANSPORT=redis beaver

Example 4: Zeromq listening on port 5556 (all interfaces):

ZEROMQ_ADDRESS="tcp://*:5556" beaver -m bind

# logstash config:
input { zeromq {
    type => 'shipper-input'
    mode => 'client'
    topology => 'pushpull'
    address => 'tcp://shipperhost:5556'
  } }
output { stdout { debug => true } }

Example 5: Zeromq connecting to remote port 5556 on indexer:

ZEROMQ_ADDRESS="tcp://indexer:5556" beaver -m connect

# logstash config:
input { zeromq {
    type => 'shipper-input'
    mode => 'server'
    topology => 'pushpull'
    address => 'tcp://*:5556'
  }}
output { stdout { debug => true } }

Todo

  • Use python threading + subprocess in order to support usage of yield across all operating systems

  • Fix usage on non-linux platforms - file.readline() does not work as expected on OS X. See above for potential solution

  • More transports

  • ~Separate tranports into different files so that individual transport requirements are not required on all installations (libzmq)~

  • ~Create a python package~

  • Ability to specify files, tags, and other metadata within a configuration file

Credits

Based on work from Giampaolo and Lusis:

Real time log files watcher supporting log rotation.

Original Author: Giampaolo Rodola' <g.rodola [AT] gmail [DOT] com>
http://code.activestate.com/recipes/577968-log-watcher-tail-f-log/

License: MIT

Other hacks (ZMQ, JSON, optparse, ...): lusis

Metadata

Release files for Beaver 1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for Beaver 1
File Size Uploaded
Beaver-1.tar.gz 6.6 kB Details

Release files / Beaver-1.tar.gz

Download URL Beaver-1.tar.gz
Size 6.6 kB
Tags Source
SHA-256 checksum
How to use checksums
16792a63ed2a08e55cd43e6ec1909978d22aa4a8c9fcdd1cb5987d7b9664c61f
BLAKE2b-256 checksum
How to use checksums
c2bd2bedce5d4bafe5c954a9c8e1beffd7a7d38b48c02471e76f8598ffff4975
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

36.3.0

2 release files

36.2.1

2 release files

36.2.0

2 release files

36.1.0

2 release files

36.0.1

2 release files

36.0.0

1 release file

35.0.2

1 release file

35.0.1

1 release file

35.0.0

1 release file

34.1.0

1 release file

34.0.1

1 release file

34.0.0

1 release file

33.3.0

1 release file

33.2.0

1 release file

33.1.0

1 release file

33.0.0

1 release file

32

1 release file

31

1 release file

30

1 release file

29

1 release file

28

1 release file

27

1 release file

26

1 release file

25

1 release file

24

1 release file

23

1 release file

22

1 release file

21

1 release file

20

1 release file

19

1 release file

18

1 release file

17

1 release file

16

1 release file

15

1 release file

14

1 release file

13

1 release file

12

1 release file

11

1 release file

10

1 release file

9

1 release file

8

1 release file

7

1 release file

6

1 release file

5

1 release file

4

1 release file

3

1 release file

2

1 release file

This release

1 This release

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page