[root@dr-mysql01 frontend-error]# cat logstash_error.conf input { file { type => "zj_frontend_error" path => ["/data01/applog_backup/zjzc_log/zj-frontend0*error*"] } file { type => "wj_frontend_error" path => ["/data01/applog_backup/winfae_log/wj-frontend0*error*"] } } filter { grok { match => [ "message" , "(?<timestamp>%{YEAR}[./-]%{MONTHNUM}[./-]%{MONTHDAY}[- ]%{TIME}) \[%{LOGLEVEL:severity}\] %{POSINT:pid}#%{NUMBER}: (?:, client: (?<clientip>%{IP}|%{HOSTNAME}))(?:, server: %{IPORHOST:server}?)(?:, request: %{QS:request})?(?:, upstream: (?<upstream>\"%{URI}\"|%{QS}))?(?:, host: %{QS:request_host})?(?:, referrer: \"%{URI:referrer}\")?"] } } output { if [type] == "zj_frontend_error" { redis { host => "192.168.32.67" data_type => "list" key => "zj_frontend_error:redis" port=>"6379" password => "1234567" } } else if [type] == "wj_frontend_error"{ redis { host => "192.168.32.67" data_type => "list" key => "wj_frontend_error:redis" port=>"6379" password => "1234567" } } } You have mail in /var/spool/mail/root [root@dr-mysql01 frontend-error]# cat logstash_indexer.conf input { redis { host => "192.168.32.67" data_type => "list" key => "zj_frontend_error:redis" password => "1234567" port =>"6379" } redis { host => "192.168.32.67" data_type => "list" key => "wj_frontend_error:redis" password => "1234567" port =>"6379" } } output { if [type] == "zj_frontend_error"{ elasticsearch { hosts => "192.168.32.80:9200" index => "logstash-zjzc-frontend-error-%{+YYYY.MM.dd}" } stdout { codec => rubydebug } } else if [type] == "wj_frontend_error"{ elasticsearch { hosts => "192.168.32.81:9200" index => "logstash-wj-frontend-error-%{+YYYY.MM.dd}" } stdout { codec => rubydebug } } }
logstash 分析nginx 错误日志
转载本文章为转载内容,我们尊重原作者对文章享有的著作权。如有内容错误或侵权问题,欢迎原作者联系我们进行内容更正或删除文章。
提问和评论都可以,用心的回复会被更多人看到
评论
发布评论
相关文章
-
logstash java错误日志合成 logstash解析日志字段
在存储您的第一个事件中,您创建了一个基本的 Logstash 管道来测试 Logstash 设置。在现实世界中,一个日志藏匿处 管道有点复杂:它通常有一个或多个输入、过滤器和输出插件。在本节中,您将创建一个 Logstash 管道,该管道使用 Filebeat 将 Apache Web 日志作为输入,解析这些日志 日志以从日志中创建特定的命名字段,并将解析后的数据写入 Elasticsearch
logstash java错误日志合成 elasticsearch 搜索引擎 大数据 Powered by 金山文档