Logstash 配置總結

來源:互聯網
上載者:User
#整個設定檔分為三部分:input,filter,output
#參考這裡的介紹 https://www.elastic.co/guide/en/logstash/current/configuration-file-structure.html
input {
  #file可以多次使用,也可以唯寫一個file而設定它的path屬性配置多個檔案實現多檔案監控
  file {
    #type是給結果增加了一個屬性叫type值為"<xxx>"的條目。這裡的type,對應了ES中index中的type,即如果輸入ES時,沒有指定type,那麼這裡的type將作為ES中index的type。
    type => "apache-access" 
    path => "/apphome/ptc/Windchill_10.0/Apache/logs/access_log*"
    #start_position可以設定為beginning或者end,beginning表示從頭開始讀取檔案,end表示讀取最新的,這個也要和ignore_older一起使用。
    start_position => beginning
    #sincedb_path表示檔案讀取進度的記錄,每行表示一個檔案,每行有兩個數字,第一個表示檔案的inode,第二個表示檔案讀取到的位置(byteoffset)。預設為$HOME/.sincedb*
    sincedb_path => "/opt/logstash-2.3.1/sincedb_path/access_progress"
    #ignore_older表示了針對多久的檔案進行監控,預設一天,單位為秒,可以自己定製,比如預設唯讀取一天內被修改的檔案。
    ignore_older => 604800
    #add_field增加屬性。這裡使用了${HOSTNAME},即原生環境變數,如果要使用原生環境變數,那麼需要在啟動命令上加--alow-env。
    add_field => {"log_hostname"=>"${HOSTNAME}"}
    #這個值預設是\n 分行符號,如果設定為空白"",那麼後果是每個字元代表一個event
    delimiter => ""
    #這個表示關閉超過(預設)3600秒後追蹤檔案。這個對於multiline來說特別有用。... 這個參數和logstash對檔案的讀取方式有關,兩種方式read tail,如果是read
    close_older => 3600
    coodec => multiline {
      pattern => "^\s"
      #這個negate是否定的意思,意思跟pattern相反,也就是不滿足patter的意思。
#      negate => ""
      #what有兩個值可選 previous和next,舉例說明,java的異常從第二行以空格開始,這裡就可以pattern匹配空格開始,what設定為previous意思是空格開頭這行跟上一行屬於同一event。另一個例子,有時候一條命令太長,當以\結尾時表示這行屬於跟下一行屬於同一event,這時需要使用negate=>true,what=>'next'。
      what => "previous"
      auto_flush_interval => 60
    }
  }
  file { 
    type => "methodserver-log" 
    path => "/apphome/ptc/Windchill_10.0/Windchill/logs/MethodServer-1604221021-32380.log" 
    start_position => beginning 
    sincedb_path => "/opt/logstash-2.3.1/sincedb_path/methodserver_process"
#    ignore_older => 604800
  }
}
filter{
  #執行ruby程式,下面例子是將日期轉化為字串賦予daytag
  ruby {
    code => "event['daytag'] = event.timestamp.time.localtime.strftime('%Y-%m-%d')"
  }
  # if [path] =~ "access" {} else if [path] =~ "methodserver" {} else if [path] =~ "servermanager" {} else {} 注意語句結構
  if [path] =~ "MethodServer" { #z這裡的=~是匹配Regex
    grok {
      patterns_dir => ["/opt/logstash-2.3.1/patterns"] #自訂正則匹配
#      Tue 4/12/16 14:24:17: TP-Processor2: hirecode---->77LS
      match => { "message" => "%{DAY:log_weekday} %{DATE_US:log_date} %{TIME:log_time}: %{GREEDYDATA:log_data}"}
    }
    #mutage是做轉換用的
    mutate { 
      replace => { "type" => "apache" } #替換屬性值
      convert => { #類型轉換
        "bytes" => "integer" #例如還有float
        "duration" => "integer"
        "state" => "integer"
      }
    #date主要是用來處理檔案內容中的日期的。內容中讀取的是字串,通過date將它轉換為@timestamp。參考https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html#plugins-filters-date-match
#    date {
#      match => [ "logTime" , "dd/MMM/yyyy:HH:mm:ss Z" ]
#    }
  }else if [type] in ['tbg_qas','mbg_pre'] { # if ... else if ... else if ... else結構
  }else {
    drop{} # 將event丟棄
  }
}
output {
  stdout{ codec=>rubydebug} # 直接輸出,調試用起來方便
  # 輸出到redis
  redis {
    host => '10.120.20.208'
    data_type => 'list'
    key => '10.99.201.34:access_log_2016-04'
  }
  # 輸出到ES
  elasticsearch {
    hosts =>"192.168.0.15:9200"
    index => "%{sysid}_%{type}"
    document_type => "%{daytag}"
  }

}




聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.