logstash解析系統的messages日誌
阿新 • • 發佈:2018-07-27
ash set times sta elastic 調試 移除 pro mmm logstash解析系統日誌的寫法,output中的stdout為調試,生產可以移除
input { redis { host => "192.168.1.181" port => 6379 db => "0" data_type => "list" key => "815" } } filter { grok { match => { "message" => "%{SYSLOGLINE}" } } mutate { remove_field => ["prospector","logsource","beat","[message][0]","offset","@version","input"] } date { match => ["timestamp","MMM dd HH:mm:ss"] } mutate { remove_field => ["timestamp"] } } output { elasticsearch { hosts => ["10.78.1.184:9200","10.78.1.185:9200","10.78.1.188:9200"] index => "message-%{+YYYY.MM.dd}" } stdout { codec => rubydebug } }
logstash解析系統的messages日誌