单文件文本同步到ES
input {
file {
path=> [ "C:/JWD/logs/*.log" ]
#path=> [ "C:/JWD/server/nginx/logs/*.log",
# "C:/JWD/server/Debug/log/*.log" ]
start_position => beginning
stat_interval => 1 #设置多长时间检测文件是否修改 默认是1s
#tags => "test" #添加标签
#设置多长时间扫描目录,发现新文件
discover_interval => 15
# 设置监听间隔 各字段含义(从左至右)分、时、天、月、年,全为*默认含义为每分钟都更新
}
}
filter {
json{
source => "message"
}
mutate{
remove_field => ["message"]
#add_field => {"test"=>"test"}
}
# mutate{
# remove_field => ["host","path","message","@timestamp","@version"]
# }
}
#https://blog.csdn.net/zhousenshan/article/details/81023857
#https://blog.csdn.net/yelllowcong/article/details