# 1
grok {
match => { "message" => "^\[%{TIMESTAMP_ISO8601:asctime}\] %{LOGLEVEL:levelname} %{URIPATH:pathname} %{NUMBER:lineno} %{WORD:funcName} %{NUMBER:process} %{NUMBER:thread} %{GREEDYDATA:messages}"}
}
# 2 部署filebeat写到Kafka
Exiting: error initializing publisher: unknown/unsupported kafka version '0.10.0.1' accessing 'output.kafka' (source:'/data/etc/filebeat.yml')