日志格式为:
192.168.1.1 - - [26/Apr/2018:00:01:01 +0800] "GET /zxl/api/mail/findList?pageNo=1&pageSize=10 HTTP/1.1" 200 449
logstash filter 配置为:
filter {
grok {
match => {"message" => "%{IPV4:clientIp} - - \[%{HTTPDATE:timestamp}\] \"%{WORD:methed}
%{URIPATH:requestUri}(?:%{URIPARAM:params})? HTTP/%{NUMBER:httpversion}\" %{NUMBER:status} %{NUMBER:bytes}"
}
}
}