input {
file {
path => "/usr/share/logstash/logstash-tutorial-dataset"
type => "elasticsearch"
start_position => "beginning" #从文件开始处读写
sincedb_path => "/usr/share/logstash/offset/test_feedback_06.access"
}
}
filter {
ruby {
code => "event.set('timestamp', event.get('@timestamp').time.localtime + 8*60*60)"
}
ruby {
code => "event.set('@timestamp',event.get('timestamp'))"
}
}
output{
elasticsearch{
hosts=>"es-nodeport-svc:9200"
index => "es-message-%{+YYYY.MM.dd}"
}
stdout{codec => rubydebug}
}
logstash @timestamp相差8小时
最新推荐文章于 2022-03-01 09:48:36 发布