ini logstash.conf
Posted
tags:
篇首语:本文由小常识网(cha138.com)小编为大家整理,主要介绍了ini logstash.conf相关的知识,希望对你有一定的参考价值。
input {
udp {
host => "0.0.0.0"
port => 5228
codec => syslog
}
}
output {
elasticsearch_http {
user => "ES_USER"
password => "ES_PASSWORD"
host => "ES_HOST"
port => "ES_PORT"
}
}
ini logstash_linked.conf
input {
tcp {
type => "iis"
port => 514
codec => "json_lines"
#Disable timeouts as logstash may drop events when timing out
data_timeout => -1
}
file {
type => "syslog"
path => [ "/var/log/*.log", "/var/log/messages", "/var/log/syslog" ]
start_position => "beginning"
}
}
filter {
if [type] == "iis" {
if [message] =~ "^#" {
drop {}
}
grok {
match => [
"message", "<%{POSINT:syslog_pri}>%{SYSLOGTIMESTAMP} %{WORD:servername} %{TIMESTAMP_ISO8601} %{IP:hostip} %{WORD:method} %{URIPATH:request} (?:%{NOTSPACE:query}|-) %{NUMBER:port} (?:%{NOTSPACE:param}|-) %{IPORHOST:clientip} %{NOTSPACE:agent} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:bytes} %{NUMBER:time-taken}",
"message", "<%{POSINT:syslog_pri}>%{SYSLOGTIMESTAMP} %{WORD:servername} %{GREEDYDATA:syslog_message}"
]
}
date {
match => ["eventtime", "YY-MM-dd HH:mm:ss"]
}
mutate {
replace => [ "@source_host", "%{servername}" ]
}
mutate {
replace => [ "@message", "%{message}" ]
}
geoip {
source => "clientip"
target => "geoip"
add_field => [ "[geoip][coordinates]", "%{[geoip][longitude]}" ]
add_field => [ "[geoip][coordinates]", "%{[geoip][latitude]}" ]
}
mutate {
convert => [ "[geoip][coordinates]", "float" ]
}
}
}
output {
elasticsearch_http {
host => "ES_HOST"
port => "ES_PORT"
}
}
以上是关于ini logstash.conf的主要内容,如果未能解决你的问题,请参考以下文章
ini logstash_linked.conf
ini logstash_syslog_shipper.conf
ini 用于Syslog输入的Logstash Conf Filter
logstash.conf配置
logstash.conf示例
logstash.conf示例