#整個設定檔分為三部分:input,filter,output
#參考這裡的介紹 https://www.elastic.co/guide/en/logstash/current/configuration-file-structure.html
input {
#file可以多次使用,也可以唯寫一個file而設定它的path屬性配置多個檔案實現多檔案監控
file {
#type是給結果增加了一個屬性叫type值為"<xxx>"的條目。這裡的type,對應了ES中index中的type,即如果輸入ES時,沒有指定type,那麼這裡的type將作為ES中index的type。
type => "apache-access"
path => "/apphome/ptc/Windchill_10.0/Apache/logs/access_log*"
#start_position可以設定為beginning或者end,beginning表示從頭開始讀取檔案,end表示讀取最新的,這個也要和ignore_older一起使用。
start_position => beginning
#sincedb_path表示檔案讀取進度的記錄,每行表示一個檔案,每行有兩個數字,第一個表示檔案的inode,第二個表示檔案讀取到的位置(byteoffset)。預設為$HOME/.sincedb*
sincedb_path => "/opt/logstash-2.3.1/sincedb_path/access_progress"
#ignore_older表示了針對多久的檔案進行監控,預設一天,單位為秒,可以自己定製,比如預設唯讀取一天內被修改的檔案。
ignore_older => 604800
#add_field增加屬性。這裡使用了${HOSTNAME},即原生環境變數,如果要使用原生環境變數,那麼需要在啟動命令上加--alow-env。
add_field => {"log_hostname"=>"${HOSTNAME}"}
#這個值預設是\n 分行符號,如果設定為空白"",那麼後果是每個字元代表一個event
delimiter => ""
#這個表示關閉超過(預設)3600秒後追蹤檔案。這個對於multiline來說特別有用。... 這個參數和logstash對檔案的讀取方式有關,兩種方式read tail,如果是read
close_older => 3600
coodec => multiline {
pattern => "^\s"
#這個negate是否定的意思,意思跟pattern相反,也就是不滿足patter的意思。
# negate => ""
#what有兩個值可選 previous和next,舉例說明,java的異常從第二行以空格開始,這裡就可以pattern匹配空格開始,what設定為previous意思是空格開頭這行跟上一行屬於同一event。另一個例子,有時候一條命令太長,當以\結尾時表示這行屬於跟下一行屬於同一event,這時需要使用negate=>true,what=>'next'。
what => "previous"
auto_flush_interval => 60
}
}
file {
type => "methodserver-log"
path => "/apphome/ptc/Windchill_10.0/Windchill/logs/MethodServer-1604221021-32380.log"
start_position => beginning
sincedb_path => "/opt/logstash-2.3.1/sincedb_path/methodserver_process"
# ignore_older => 604800
}
}
filter{
#執行ruby程式,下面例子是將日期轉化為字串賦予daytag
ruby {
code => "event['daytag'] = event.timestamp.time.localtime.strftime('%Y-%m-%d')"
}
# if [path] =~ "access" {} else if [path] =~ "methodserver" {} else if [path] =~ "servermanager" {} else {} 注意語句結構
if [path] =~ "MethodServer" { #z這裡的=~是匹配Regex
grok {
patterns_dir => ["/opt/logstash-2.3.1/patterns"] #自訂正則匹配
# Tue 4/12/16 14:24:17: TP-Processor2: hirecode---->77LS
match => { "message" => "%{DAY:log_weekday} %{DATE_US:log_date} %{TIME:log_time}: %{GREEDYDATA:log_data}"}
}
#mutage是做轉換用的
mutate {
replace => { "type" => "apache" } #替換屬性值
convert => { #類型轉換
"bytes" => "integer" #例如還有float
"duration" => "integer"
"state" => "integer"
}
#date主要是用來處理檔案內容中的日期的。內容中讀取的是字串,通過date將它轉換為@timestamp。參考https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html#plugins-filters-date-match
# date {
# match => [ "logTime" , "dd/MMM/yyyy:HH:mm:ss Z" ]
# }
}else if [type] in ['tbg_qas','mbg_pre'] { # if ... else if ... else if ... else結構
}else {
drop{} # 將event丟棄
}
}
output {
stdout{ codec=>rubydebug} # 直接輸出,調試用起來方便
# 輸出到redis
redis {
host => '10.120.20.208'
data_type => 'list'
key => '10.99.201.34:access_log_2016-04'
}
# 輸出到ES
elasticsearch {
hosts =>"192.168.0.15:9200"
index => "%{sysid}_%{type}"
document_type => "%{daytag}"
}
}