1、多行显示问题
filter中配置如下:
#解决日志多行问题,匹配以[开头的
multiline {
pattern => "^\["
negate => true
#"previous" 指代合并到前一行,"next"指代合并到下一行中
what => "previous"
}
启动multiline 报错
解决方式如下:
查看是否安装插件logstash-filter-multiline:./logstash-plugin list
如果没有则安装插件:./logstash-plugin install logstash-filter-multiline
2、8小时时差问题(filter过滤器中添加)
#解决8小时时差问题
ruby {
code => "event.set('timestamp', event.get('@timestamp').time.localtime + 8*60*60)"
}
ruby {
code => "event.set('@timestamp',event.get('timestamp'))"
}
mutate {
remove_field => ["timestamp"]
}