1. 程式人生 > >logstash 中多行合並

logstash 中多行合並

mem class clas inpu users code dir body bundle

這裏我之前是在input裏面配置的多行合並,合並語法為:

input {
        beats {
          type => beats
          port => 7001
          codec => multiline {
            patterns_dir => ["/data/package/logstash/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-2.0.2/patterns"]
            pattern => ".*#ELK#.*"
            what => "previous"
            negate => true

        }
        }
}

這裏我們也可以再filter裏面使用multiline插件來合並多行

logstash 在filter裏設置多行合並 
filter {
  multiline {
    pattern => ".*TRACE.*"
    what => "previous"
  }
}

https://groups.google.com/forum/#!topic/logstash-users/7LFyeIQMmEM

logstash 中多行合並