elk組件 基礎文法

來源:互聯網
上載者:User

標籤:elk

Shipper->Broker->Indexer->ES1.inputinput { stdin {} }output {   stdout { codec=> rubydebug }}file {   codec => multiline { pattern => "^\s" what => "previous"}   path => ["xx","xx"]   exclude => "1.log"   add_field => [ "log_ip", "xx" ]   tags => "tag1"   #設定新事件的標誌   delimiter => "\n"   #設定多長時間掃描目錄,發現新檔案   discover_interval => 15   #設定多長時間檢測檔案是否修改   stat_interval => 1   #監聽檔案的起始位置,預設是end   start_position => beginning   #監聽檔案讀取資訊記錄的位置   sincedb_path => "E:/software/logstash-1.5.4/logstash-1.5.4/test.txt"   #設定多長時間會寫入讀取的位置資訊   sincedb_write_interval => 15   }      2.filter filter {    multiline {        # 指定合并規則——所有不是以數字開頭的行需要被合并        pattern => "^[^\d]"        # 合并到哪裡——上一行        what => "previous"    }  filter {  multiline {    type => "type"   #類型,不多說    pattern => "pattern, a regexp" #參數,也可以認為是字元,有點像grep ,如果符合什麼字元就交給下面的 what 去處理    negate => boolean    what => "previous" or "next" #這個是符合上面 pattern 的要求後具體怎麼處理,處理方法有兩種,合并到上面一條日誌或者下面的日誌  }}      filter {  grep {    match => [ "@message", "PHP Fatal error" ]    drop  => false    add_tag => [fatal_error]       }                                                          grep {       tags => [fatal_error]       match => [ "@message", ".*(xbox\.com|xbox\.mib\.com\.cn|supports\.game\.mib\.com\.cn)" ]       drop  => false       add_tag => [xboxerror]            }         } #過濾掉內容包含5.3.3與down以外日誌filter {    if [message] !~  "5.3.3|down" {        ruby  {            code => "event.cancel"    }    }}#使用內建的過濾規則顯示更多的欄位filter {    grok {        match => {"message" => "%{COMBINEDAPACHELOG}"}  }}#合并不是以[開頭的日誌filter {    multiline {        pattern => "^[^[]"        negate => true        what => "previous"    }}  filter {  if [path] =~ "error" {    mutate { replace => { "type" => "apache_error" } }    grok {      match => { "message" => "%{COMBINEDAPACHELOG}" }    }  }  date {    match => [ "timestamp" , "dd/MMM/yyyy:HH:mm:ss Z" ]  }}   filter {  if [path] =~ "access" {    mutate { replace => { type => "apache_access" } }    grok {      match => { "message" => "%{COMBINEDAPACHELOG}" }    }    date {      match => [ "timestamp" , "dd/MMM/yyyy:HH:mm:ss Z" ]    }  } else if [path] =~ "error" {    mutate { replace => { type => "apache_error" } }  } else {    mutate { replace => { type => "random_logs" } }  }}  3.output發郵件output {email {   match => [ "@message", "aaaaa" ]   to => "[email protected]"   from => "[email protected]"   options => [ "smtpIporHost", "smtp.mibnet.com",                "port", "25",                "userName", "[email protected]",                "starttls", "true",                "password", "opmonitor",                "authenticationType", "login"              ]   subject => "123"   body => ‘123‘   via => smtp}}      output {    if [type] == "syslog" {        elasticsearch {            hosts => "172.16.0.102:9200"            index => "syslog-%{+YYYY.MM.dd}"    }}         if [type] == "nginx" {        elasticsearch {            hosts => "172.16.0.102:9200"            index => "nglog-%{+YYYY.MM.dd}"     }}#匹配內容包含paramiko與simplejson的日誌通郵件發送    if [message] =~  /paramiko|simplejson/ {        email {            to => "[email protected]"            from => "[email protected]"            contenttype => "text/plain; charset=UTF-8"            address => "smtp.163.com"            username => "[email protected]"            password => "12344"            subject => "伺服器%{host}日誌異常"            body => "%{@timestamp} %{type}: %{message}"        }    }}       output {    stdout { codec => rubydebug }    redis {        host => ‘192.168.1.104‘        data_type => ‘list‘        key => ‘logstash:redis‘    }}   output {  elasticsearch { host => localhost }  stdout { codec => rubydebug }}      替換mutate {    type => "phplog"    gsub => [ "@message","‘", "\"" ]}   調試# /usr/local/logstash-1.5.2/bin/logstash -e ‘input { stdin { } } output { stdout {} }‘curl ‘ logstash -e ‘input{stdin{}}output{stdout{codec=>rubydebug}}‘

# logstash agent -f logstash-simple.conf --verbose //開啟debug模式




本文出自 “人,要有自己的想法” 部落格,請務必保留此出處http://szgb2016.blog.51cto.com/340201/1865408

elk組件 基礎文法

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.