LogSearch整合Elasticsearch出错
logstash同步数据到ES时,刚启动就shut down的问题:
1、错误信息
错误推测:
- 可能是配置文件写错
- 启动的路径写错了
2、日志信息
上诉情况都检查了无误,查看了日志信息发现如下
错误原因:Unknown setting ‘host’ for elasticsearch
解决方案:host修改为 hosts即可
3、配置文件
input {
file {
path => ["C:/Users/SayHello/Desktop/log/nginx.log"]
start_position => "beginning"
}
}
filter {
grok {
match => { "message" => "%{IP:clientip}\ \[%{HTTPDATE:timestamp}\]\ %{QS:referrer}\ %{NUMBER:response}\ %{NUMBER:bytes}" }
remove_field => [ "message" ]
}
date {
match => ["timestamp", "dd/MMM/yyyy:HH:mm:ss Z"]
}
mutate {
rename => { "response" => "response_new" }
convert => [ "response","float" ]
gsub => ["referrer","\"",""]
remove_field => ["timestamp"]
split => ["clientip", "."]
}
}
output {
elasticsearch {
hosts => ["127.0.0.1:9200"]
index => "logstash-%{+YYYY.MM.dd}"
}
}