例如, syslog 事件通常有时间戳如下:
你需要使用 事件戳 MMM dd HH:mm:ss来解析
Apr 17 09:32:01 test20201202
Apr 17 09:32:01 test20201202
Apr 17 09:32:01 test20201202
Apr 06 10:32:01 test20201202
Jan 06 10:59:01 test20201202
Jan 06 10:59:59 test20201202
[elk@node2 conf]$ logstash -f logstash01.conf
!!! Please upgrade your java version, the current version '1.7.0_45-mockbuild_2013_11_22_18_30-b00' may cause problems. We recommend a minimum version of 1.7.0_51
Settings: Default pipeline workers: 4
Pipeline main started
{
"message" => "Apr 17 09:32:01 test20201202",
"@version" => "1",
"@timestamp" => "2020-10-05T18:57:41.312Z",
"path" => "/home/elk/conf/test.txt",
"host" => "node2",