logstash 配置


input {
file {
type => "fx-czrz"
path => ["D:/logs1/czrzFile*"]
start_position => "beginning"
}
file{
path => "D:/logs2/ycrzFile*"
type => "fx-ycrz"
start_position => beginning
#codec => multiline{
# pattern => "^\s"
# what => "previous"
#}
}
jdbc {
jdbc_connection_string => "jdbc:mysql://127.0.0.1:3306/test"
jdbc_user => "root"
jdbc_password => "123456"
jdbc_driver_library => "E:\mysql-driver\mysql-connector-java-5.1.44-bin.jar"
jdbc_driver_class => "com.mysql.jdbc.Driver"
#定时字段 各字段含义(由左至右)分、时、天、月、年,全部为*默认含义为每分钟都更新(测试结果,不同的话请留言指出)
schedule => "* * * * *"
jdbc_default_timezone => "Asia/Shanghai"
#以下对应着要执行的sql的绝对路径。
statement_filepath => "e:\ls\sql.sql"
use_column_value => false
last_run_metadata_path => "e:\ls\last_run.txt"
jdbc_paging_enabled => "true"
jdbc_page_size => "50000"
#设定ES索引类型
type => "mysqlrz"
}
# stdin {} #可以从标准输入读数据
}
filter {
if [type] == "fx-czrz" {
grok{
match => { "message" => "\[%{TIMESTAMP_ISO8601:timestamp}\] \[%{DATA:xtlx}\] \[%{DATA:traceId}\] \[%{LOGLEVEL:log_level}\] \[(?<ffmc>(.*))\] %{GREEDYDATA:qqsj}%{GREEDYDATA:ip}%{GREEDYDATA:zh}%{GREEDYDATA:xm}%{GREEDYDATA:url}%{WORD:method}%{GREEDYDATA:params}(?<agent>(.*))" }
match => { "message" => "\[%{TIMESTAMP_ISO8601:timestamp}\] \[%{DATA:xtlx}\] \[%{DATA:traceId}\] \[%{LOGLEVEL:log_level}\] \[(?<ffmc>(.*))\] %{GREEDYDATA:qqsj}%{GREEDYDATA:ip}%{GREEDYDATA:zh}%{GREEDYDATA:xm}%{GREEDYDATA:url}%{WORD:method}%{GREEDYDATA:params}(?<agent>(.*))" }
match => { "message" => "\[%{TIMESTAMP_ISO8601:timestamp}\] \[%{DATA:xtlx}\] \[%{DATA:traceId}\] \[%{LOGLEVEL:log_level}\] \[(?<ffmc>(.*))\] ==>%{GREEDYDATA:message}" }
match => { "message" => "\[%{TIMESTAMP_ISO8601:timestamp}\] \[%{DATA:xtlx}\] \[%{DATA:traceId}\] \[%{LOGLEVEL:log_level}\] \[(?<ffmc>(.*))\] <==%{GREEDYDATA:message}" }
match => { "message" => "\[%{TIMESTAMP_ISO8601:timestamp}\] \[%{DATA:xtlx}\] \[%{DATA:traceId}\] \[%{LOGLEVEL:log_level}\] \[(?<ffmc>(.*))\] %{GREEDYDATA:message}" }
match => { "message" => "%{GREEDYDATA:message}" }
}
date{
match => ["timestamp","UNIX_MS"]
remove_field => "timestamp"
}
urldecode{
all_fields => true
}
}
}
output {
if [type] == "mysqlrz"{
elasticsearch {
hosts => ["localhost:9200"]
index => "mysqlrz_%{+YYYYMMdd}"
user => "elastic"
password => "123456"
}
}
if [type] == "fx-czrz"{
elasticsearch {
hosts => ["localhost:9200"]
index => "fx-czrz-%{+YYYYMMdd}"
user => "elastic"
password => "123456"
}
}
if [type] == "fx-ycrz"{
elasticsearch {
hosts => ["localhost:9200"]
index => "fx-ycrz-%{+YYYYMM}"
user => "elastic"
password => "123456"
}
}
}

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值