1. 程式人生 > >logstash 匹配日誌格式

logstash 匹配日誌格式

min bsp time sta color output put sage nbsp

2017-05-15 12:06:17 INFO me.cinyi.imapp.push.commons.iospush - 用戶ID[1000]-標識[11500], admin推送通知成功, messages:[6921]ms

input {
        stdin{}
}

filter {
    grok{
       #match => {"message" => "%{WORD:method}"}
       #match => {"message" => "(?:%{SYSLOGTIMESTAMP:syslog_timestamp}|%{TIMESTAMP_ISO8601:timestamp8601}) %{WORD:method} %{GREEDYDATA:pushios} %{NUMBER:costs} \[${WORD:ms}
"} match => {"message" => "(?:%{SYSLOGTIMESTAMP:syslog_timestamp}|%{TIMESTAMP_ISO8601:timestamp8601}) %{WORD:method} %{GREEDYDATA:pushios} %{WORD:method}\:\[%{NUMBER:costes}\]%{WORD:sencode}"} } } output { stdout{ codec => rubydebug } }

logstash 匹配日誌格式