#logstash中grok插件的使用
#grok中match插件的使用
grok {
#提取字段
match => {
"source" => "(\w+/){2}(?<project>.*?)/.*"
}
}
mutate {
#重写字段
rename => {
"project" => "proj"
}
}
mutate {
#去掉没用字段
remove_field => ["input_type","count","tags","@version","fields","offset","txt","level_name"]
}