logstash 匹配日誌格式
阿新 • • 發佈:2017-05-18
min bsp time sta color output put sage nbsp
2017-05-15 12:06:17 INFO me.cinyi.imapp.push.commons.iospush - 用戶ID[1000]-標識[11500], admin推送通知成功, messages:[6921]ms
input { stdin{} } filter { grok{ #match => {"message" => "%{WORD:method}"} #match => {"message" => "(?:%{SYSLOGTIMESTAMP:syslog_timestamp}|%{TIMESTAMP_ISO8601:timestamp8601}) %{WORD:method} %{GREEDYDATA:pushios} %{NUMBER:costs} \[${WORD:ms}"} match => {"message" => "(?:%{SYSLOGTIMESTAMP:syslog_timestamp}|%{TIMESTAMP_ISO8601:timestamp8601}) %{WORD:method} %{GREEDYDATA:pushios} %{WORD:method}\:\[%{NUMBER:costes}\]%{WORD:sencode}"} } } output { stdout{ codec => rubydebug } }
logstash 匹配日誌格式