- filter {
- grok {
- match => [
- "message" , "\s*%{IPORHOST:clientip}\s+\-\s+\-\s+
- "message" ,"\s*%{IPORHOST:clientip}\s+\-\s+\-\s+
- "message" ,"\s*%{IPORHOST:clientip}\s+\-\s+\-\s+
- ]
- }
- mutate {
- convert => [ "request_time", "float"]
- add_field =>["response_time","%{request_time}"]
- remove_field =>["request_time"]
- }
- date {
- match => ["time", "dd/MMM/yyyy:HH:mm:ss Z"]
- }
- }
logstash 字段类型转换后 需要刷新
最新推荐文章于 2024-04-07 10:56:04 发布