ini logstash.conf

Posted

tags:

篇首语:本文由小常识网(cha138.com)小编为大家整理,主要介绍了ini logstash.conf相关的知识,希望对你有一定的参考价值。

input {
  udp {
    host => "0.0.0.0"
    port => 5228
    codec => syslog
  }
}

output {
  elasticsearch_http {
    user => "ES_USER"
    password => "ES_PASSWORD"
    host => "ES_HOST"
    port => "ES_PORT"
  }
}

ini logstash_linked.conf

input {
  tcp {
    type => "iis"
    port => 514
    codec => "json_lines"
    #Disable timeouts as logstash may drop events when timing out
    data_timeout => -1
  }
  
  file {
    type => "syslog"
    path => [ "/var/log/*.log", "/var/log/messages", "/var/log/syslog" ]
    start_position => "beginning"
  }
}
filter {  
  if [type] == "iis" {
    if [message] =~ "^#" {
      drop {}
    }
    grok {
      match => [
        "message", "<%{POSINT:syslog_pri}>%{SYSLOGTIMESTAMP} %{WORD:servername} %{TIMESTAMP_ISO8601} %{IP:hostip} %{WORD:method} %{URIPATH:request} (?:%{NOTSPACE:query}|-) %{NUMBER:port} (?:%{NOTSPACE:param}|-) %{IPORHOST:clientip} %{NOTSPACE:agent} %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:bytes} %{NUMBER:time-taken}",
        "message", "<%{POSINT:syslog_pri}>%{SYSLOGTIMESTAMP} %{WORD:servername} %{GREEDYDATA:syslog_message}"
      ]
    }
    date {
      match => ["eventtime", "YY-MM-dd HH:mm:ss"]
    }
    mutate {
      replace => [ "@source_host", "%{servername}" ]
    }
    mutate {
      replace => [ "@message", "%{message}" ]
    }
    geoip {
      source => "clientip"
      target => "geoip"
      add_field => [ "[geoip][coordinates]", "%{[geoip][longitude]}" ]
      add_field => [ "[geoip][coordinates]", "%{[geoip][latitude]}"  ]
    }
    mutate {
      convert => [ "[geoip][coordinates]", "float" ]
    }
  }
}

output {
  
  elasticsearch_http {
    host => "ES_HOST"
    port => "ES_PORT"
  }
}

以上是关于ini logstash.conf的主要内容,如果未能解决你的问题,请参考以下文章

ini logstash_linked.conf

ini logstash_syslog_shipper.conf

ini 用于Syslog输入的Logstash Conf Filter

logstash.conf配置

logstash.conf示例

logstash.conf示例