---------------------------------------------------filebeat配置----------------------------------------------------------------------
filebeat.prospectors:
- input_type: log
paths:
- /mapbar/logs/nginx/jfx/2017/*/*/*.log ---日志已经被切割,按照小时分割,所以用*匹配
exclude_lines: ["nagios"] ---过滤点带有nagios的日志(监控的访问)
output.logstash:
hosts: ["10.0.1.78:5051"] ---输出给logstash
---------------------------------------------------logstash自定义匹配配置----------------------------------------------------------------------
ZIDINGYI \".*\"+? ---定义一个匹配规则
---------------------------------------------------logstash配置----------------------------------------------------------------------
input {
beats {
port => 5051
}
}
filter {
grok {
filebeat.prospectors:
- input_type: log
paths:
- /mapbar/logs/nginx/jfx/2017/*/*/*.log ---日志已经被切割,按照小时分割,所以用*匹配
exclude_lines: ["nagios"] ---过滤点带有nagios的日志(监控的访问)
output.logstash:
hosts: ["10.0.1.78:5051"] ---输出给logstash
---------------------------------------------------logstash自定义匹配配置----------------------------------------------------------------------
ZIDINGYI \".*\"+? ---定义一个匹配规则
---------------------------------------------------logstash配置----------------------------------------------------------------------
input {
beats {
port => 5051
}
}
filter {
grok {