ELK测试笔记-filebeat输出到logstash
2017-01-17 09:50
435 查看
测试说明
通过filebeat监控nginx日志(已配置为json格式)。之后直接输出到logstash。filebeat配置
增加部分:output.logstash:
# The Logstash hosts
hosts: [“192.168.100.34:5044”]
index: shopweb
logstash配置
input { beat { port => 5044 codec => json # 直接将filebeat保存在message中的json字串解析出来 } } filter { mutate { remove_field => ["tags", "beat"] #删除filebeat自动添加的字段 ## 测试发现:如果换成drop { remove_field => ## 无输出 } } output { stdout { codec => rubydebug } }
运行输出结果
{ "request" => "POST /dybuat/invest/getBorrowListPage.do?status=1 HTTP/1.1", "referer" => "http://shopweb.dev/dybuat/invest/index.html?status=1", "agent" => "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36", "offset" => 167804, "input_type" => "log", "source" => "/var/log/nginx/access.log", "type" => "log", "http_host" => "shopweb.dev", "url" => "/dybuat/invest/getBorrowListPage.do", "tags" => [ [0] "beats_input_codec_json_applied" ], "upstreamhost" => "192.168.100.121:8081", "@timestamp" => 2017-01-17T01:35:26.799Z, "size" => "13932", "clientip" => "192.168.20.32", "host" => "192.168.100.70", "@version" => "1", "responsetime" => "0.018", "xff" => "-", "fields" => { "log_source" => "shopweb" }, "upstreamtime" => "0.018", "status" => "200" }
相关文章推荐
- ELK测试笔记:filebeat与logsmash写入redis
- elk日志分析filebeat配置(filebeat + logstash)
- Linux搭建ELK日志收集系统:FIlebeat+Redis+Logstash+Elasticse
- lasticsearch 入门:Filebeat 安装及输出数据到 elasticsearch 或 logstash
- ELK 之Filebeat 结合Logstash 过滤出来你想要的日志
- ELK 架构之 Logstash 和 Filebeat 配置使用(采集过滤)
- [elk]logstash&filebeat常用语句
- ELK 架构之 Elasticsearch、Kibana、Logstash 和 Filebeat 安装配置汇总(6.2.4 版本)
- elk日志分析filebeat配置(filebeat + logstash)
- ELK 架构之 Logstash 和 Filebeat 安装配置
- ELK实战之使用filebeat代替logstash收集日志
- filebeat -> logstash -> elasticsearch -> kibana ELK 日志收集搭建
- ELKF(Elasticsearch+Logstash+ Kibana+ Filebeat) 部署
- logstash配合filebeat监控tomcat日志
- filebeat.yml配置和logstash.conf
- filebeat.yml配置和logstash.conf
- ELK+Filebeat+Kafka+ZooKeeper 构建海量日志分析平台 推荐
- ELK+Filebeat 集中式日志解决方案详解
- python fabric部署elk的filebeat日志收集客户端