Logstash logs are collected in Windows, the program that writes the log does not cut logs (Windows prompts, files are occupied)
Download usejavatoopenfile https://github.com/edwinf/ruby-filewatch/tree/useJavatoOpenFile from GitHub
wget Https://github.com/jordansissel/ruby-filewatch/archive/master.zip
After decompression
Use the Unzip tool to open Logstash-1.3.3.jar, add Java\jrubyfileextension.jar to the current directory
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/48/49/wKioL1QGvt2BVQM4AASq7V5epN4479.jpg "style=" width : 600px;height:296px; "title=" 1.jpg "width=" "height=" 296 "border=" 0 "hspace=" 0 "vspace=" 0 "alt=" Wkiol1qgvt2bvqm4aasq7v5epn4479.jpg "/>
Then add Lib\filewatch all ruby files to the Filewatch directory
650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/48/4A/wKioL1QGvyWREBX8AAGxf7SWsns852.jpg "title=" 2.jpg " Width= "height=" 290 "border=" 0 "hspace=" 0 "vspace=" 0 "style=" width:600px;height:290px; "alt=" Wkiol1qgvywrebx8aagxf7swsns852.jpg "/>
On the cmd command line, enter
Set Closeafterread=true
Then start Logstash
Java-jar Logstash-1.3.3.jar agent-f config.conf
Reference information:
http://cookbook.logstash.net/recipes/windows-service/
Http://serverfault.com/questions/563235/nxlog-file-input-search-patterns
https://logstash.jira.com/browse/LOGSTASH-986
This article is from the "Couch People" blog, please make sure to keep this source http://enable.blog.51cto.com/747951/1548326
Logstash collecting Windows Logs-resolving logs cannot rename issues