Logstash配置
插件安装
./logstash-plugin list
./logstash-plugin install logstash-input-azureblob有关Logstash的配置解读
filter Grok的示例
filter {
if "/my-log-group" in [logGroup] {
grok {
match => {
"message" => "(?<api_path>\/api\/v1\/\S+) %{WORD} %{BASE10NUM:code:int} %{NUMBER:duration}(?<unit>(s|ms|us))"
}
}
}
else {
drop {}
}
if "_grokparsefailure" in [tags] {
drop {}
}
}
解读Filter常用部分,也是对logstash配置的关键部分
Last updated