logstash配置文件

语义转换测试链接

http://grokdebug.herokuapp.com/


日志格式

  zrsname objectname 0
  zrs objec_tname 1
  zrsdddde z1ong 1
  zrsdddde z1ong1 2
  zrsdddde z1ong2 3
  zrsdddde z1ong3 4
  zrsdddde z1ong4 5
  zrsdddde z1ong5 6
  zrsdddde z1ong6 7


input{

    file {
        type => "logs"
        path => "/home/ELK/logstash-all-2.4.0/data/test.log"
        start_position => "beginning"
        #exclude => ["*.log"]
        #sincedb_path => "/dev/null"
    }   
    #stdin{type => "logs"}
}

filter {
    if [type] == "logs" {
        grok {
            #match => ["message",  "%{COMBINEDAPACHELOG}"]
            #patterns_dir => "/path/to/your/own/patterns"
            match => { "message" => "%{WORD:bucket} %{WORD:object} %{NUMBER:operate:int}"}
        }   

        #date {
        #    match => ["operatedate", "yyyy-MM-dd-HH:mm:ss"]
        #}  

        #overwrite => ["message"]
        mutate {
            remove => [ "message" ]
            remove => [ "@version" ]
            #remove => [ "@path" ]
            #remove => [ "@host" ]
            #remove => [ "@type" ]
            #add_field => {"bucket" => "%{bucketname}"
            #          "object" => "%{objectname}"
            #          "result" => "%{operateresult}"
            #          "operate" => "%{operatedate}"
            #}  
        }   
    }   
}

output {
    elasticsearch {
        index => "logstash--%{+dd.MM.YYYY}"
        hosts => "10.75.144.208"
    }   
    stdout { codec => rubydebug }

}


输出结果图片


  • 0
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值