input {
file {
path => "/var/log/messages"
type => "system"
start_position => "beginning"
}
}
input {
file {
path => "/path/to/data/lrw.log"
type => "es-error"
start_position => "beginning"
codec => multiline {
pattern => "^\["
negate => true
what => "previous"
}
}
}
output {
if [type] == "system"{
elasticsearch {
hosts => ["192.168.50.174:9200"]
index => "systemlog-%{+YYYY.MM.dd}"
}
}
if [type] == "es-error"{
elasticsearch {
hosts => ["192.168.50.174:9200"]
index => "es-error-%{+YYYY.MM.dd}"
}
}
}
收集elk错误日志和系统日志配置文件编写
最新推荐文章于 2023-04-20 11:37:37 发布