前一篇我们已经学会了logstash-input-file插件的用法,我们现在在上一篇的基础上来学习一下filter。
首先呢,还是来伪造数据
[sqczm@sqczm logstash-6.7.1]$ pwd
/opt/logstash-6.7.1
[sqczm@sqczm logstash-6.7.1]$ ls demo/second/
events.txt second.conf
[sqczm@sqczm logstash-6.7.1]$ more demo/second/events.txt
2019-04-20 20:21:00 64 bytes from 8.8.8.8: icmp_seq=1 ttl=64 time=1.720 ms
2019-04-20 20:21:01 64 bytes from 8.8.8.8: icmp_seq=2 ttl=64 time=2.197 ms
[sqczm@sqczm logstash-6.7.1]$ more demo/second/second.conf
input {
file {
path => ["/opt/logstash-6.7.1/demo/second/events.txt"]
start_position => "beginning"
}
}
filter {
}
output {
stdout {
}
}
[sqczm@sqczm logstash-6.7.1]$ bin/logstash -f demo/second/second.conf
……中间省略部分输出……
{
"@version" => "1",