nginx数据采集
1 、logstash配置目录增加配置文件 vi /etc/logstash/conf.d/nginx.conf
input {
file {
path => "/opt/www/wwwlogs/sjtclogs/*.log"
ignore_older => 0
codec => json
}
}
filter {
mutate {
convert => [ "status","integer" ]
convert => [ "size","integer" ]
convert => [ "upstreatime","float" ]
convert => ["[geoip][coordinates]", "float"]
remove_field => "message"
}
date {
match => [ "timestamp" ,"dd/mmm/yyyy:hh:mm:ss z" ]
}
mutate {
remove_field => "timestamp"
}
}
output {
elasticsearch {
hosts => ["xxx.xx.xx.xx:9200"]
index => "logstash-nginx"
user => "ela