配置文件
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28
| input { redis { host => "10.0.20.120" port => "6379" key => "nginx_log" data_type => "list" threads => "2" db => "0" type => "nginx_log" } } filter { grok { match => {"message" => "%{IPORHOST:clientip} \[%{HTTPDATE:timestap}\] %{WORD:http_methed} %{NOTSPACE:request} %{NOTSPACE:request_query} %{NUMBER:status_code} %{NUMBER:bytes} %{NOTSPACE:referer} %{QS:user_agent}"} } mutate { convert => ["bytes", "integer", "status_code", "integer"] } geoip { source => "clientip" } } output { elasticsearch { hosts => ["10.0.20.122:9200"] index => "test5-%{+YYYY.MM.dd}" } }
|
上一篇:docker swarm部署Eureka群集高可用
下一篇:shell参数替换