elasticsearch filebeat+logstash+elasticsearch加密传输测试
*****************************
配置文件
filebeat
filebeat.inputs:
- type: log
enabled: true
paths:
- /usr/share/filebeat/logs/*.log
output.logstash:
hosts: ["172.18.0.32:5044"]
logstash
管道配置文件:logstash.conf
input {
beats {
port => 5044
}
}
filter {
grok {
match => { "message" => "%{NUMBER:document_id}\s+%{GREEDYDATA:info}" }
}
mutate {
remove_field => ["host","agent","message","log","