a亚洲精品_精品国产91乱码一区二区三区_亚洲精品在线免费观看视频_欧美日韩亚洲国产综合_久久久久久久久久久成人_在线区

首頁(yè) > 學(xué)院 > 操作系統(tǒng) > 正文

logstash 字段引用

2024-06-28 16:01:14
字體:
來(lái)源:轉(zhuǎn)載
供稿:網(wǎng)友
字段引用:10.168.255.134 [09/Oct/2016:15:28:52 +0800] "GET / HTTP/1.1" - 200 23388 "" "Mozilla/5.0 (linux; U; Android 4.4.4; zh-cn; MX4 PRo Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30" 0.001 101.226.125.103[elk@Vsftp logstash]$ cat logstash.conf input {   stdin{}   }filter {    grok {        match =>[              "message","%{ipORHOST:clientip} /[%{HTTPDATE:time}/] /"%{Word:verb} %{URIPATHPARAM:request}/?.* HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"(?<http_referer>/S+)/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)",              "message" , "%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"(?<http_referer>/S+)/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)",             "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} (?<http_url>/S+)/s+HTTP/%{NUMBER:httpversion}/"/s+/-/s+%{NUMBER:http_status_code}/s+%{NUMBER:bytes}/s+/"/-/"/s+/"(?<http_user_agent>(/S+))/"/s+(%{BASE16FLOAT:request_time})/s+(%{IPORHOST:http_x_forwarded_for}|-)",             "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)"                     ]    }}output {        stdout {                        codec => rubydebug                } }[elk@Vsftp logstash]$ logstash -f logstash.conf Settings: Default pipeline workers: 4Pipeline main started10.168.255.134 [09/Oct/2016:15:28:52 +0800] "GET / HTTP/1.1" - 200 23388 "" "Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30" 0.001 101.226.125.103{                 "message" => "10.168.255.134 [09/Oct/2016:15:28:52 +0800] /"GET / HTTP/1.1/" - 200 23388 /"/" /"Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30/" 0.001 101.226.125.103",                "@version" => "1",              "@timestamp" => "2017-02-08T01:39:50.650Z",                    "host" => "Vsftp",                "clientip" => "10.168.255.134",                    "time" => "09/Oct/2016:15:28:52 +0800",                    "verb" => "GET",                 "request" => "/",             "httpversion" => "1.1",        "http_status_code" => "200",                   "bytes" => "23388",         "http_user_agent" => "Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30",            "request_time" => "0.001",    "http_x_forwarded_for" => "101.226.125.103"}[elk@Vsftp logstash]$ cat logstash.conf input {   stdin{}   }filter {    grok {        match =>[              "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request}/?.* HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"(?<http_referer>/S+)/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)",              "message" , "%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"(?<http_referer>/S+)/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)",             "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} (?<http_url>/S+)/s+HTTP/%{NUMBER:httpversion}/"/s+/-/s+%{NUMBER:http_status_code}/s+%{NUMBER:bytes}/s+/"/-/"/s+/"(?<http_user_agent>(/S+))/"/s+(%{BASE16FLOAT:request_time})/s+(%{IPORHOST:http_x_forwarded_for}|-)",             "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)"                     ]    }geoip {                        source => "http_x_forwarded_for"                        target => "geoip"                        database => "/usr/local/logstash-2.3.4/etc/GeoLiteCity.dat"                        add_field => [ "[geoip][coordinates]", "%{[geoip][longitude]}" ]                        add_field => [ "[geoip][coordinates]", "%{[geoip][latitude]}"  ]                }}output {        stdout {                        codec => rubydebug                } }[elk@Vsftp logstash]$ logstash -f logstash.conf Settings: Default pipeline workers: 4Pipeline main started10.168.255.134 [09/Oct/2016:15:28:52 +0800] "GET / HTTP/1.1" - 200 23388 "" "Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30" 0.001 101.226.125.103{                 "message" => "10.168.255.134 [09/Oct/2016:15:28:52 +0800] /"GET / HTTP/1.1/" - 200 23388 /"/" /"Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30/" 0.001 101.226.125.103",                "@version" => "1",              "@timestamp" => "2017-02-08T01:42:33.645Z",                    "host" => "Vsftp",                "clientip" => "10.168.255.134",                    "time" => "09/Oct/2016:15:28:52 +0800",                    "verb" => "GET",                 "request" => "/",             "httpversion" => "1.1",        "http_status_code" => "200",                   "bytes" => "23388",         "http_user_agent" => "Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30",            "request_time" => "0.001",    "http_x_forwarded_for" => "101.226.125.103",                   "geoip" => {                      "ip" => "101.226.125.103",           "country_code2" => "CN",           "country_code3" => "CHN",            "country_name" => "China",          "continent_code" => "AS",             "region_name" => "23",               "city_name" => "Shanghai",                "latitude" => 31.045600000000007,               "longitude" => 121.3997,                "timezone" => "Asia/Shanghai",        "real_region_name" => "Shanghai",                "location" => [            [0] 121.3997,            [1] 31.045600000000007        ],             "coordinates" => [            [0] 121.3997,            [1] 31.045600000000007        ]    }}字段引用字段引用是Logstash::Event 對(duì)象的屬性,我們之前提過(guò)事件就像一個(gè)哈希一樣,所以你可以想象字段就像一個(gè)鍵值對(duì)如果你想在Logstash 配置中使用字段的值,只需把字段的名字寫(xiě)在中括號(hào)[]里就行了,這就叫字段引用[elk@Vsftp logstash]$ cat logstash.conf input {   stdin{}   }filter {    grok {        match =>[              "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request}/?.* HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"(?<http_referer>/S+)/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)",              "message" , "%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"(?<http_referer>/S+)/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)",             "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} (?<http_url>/S+)/s+HTTP/%{NUMBER:httpversion}/"/s+/-/s+%{NUMBER:http_status_code}/s+%{NUMBER:bytes}/s+/"/-/"/s+/"(?<http_user_agent>(/S+))/"/s+(%{BASE16FLOAT:request_time})/s+(%{IPORHOST:http_x_forwarded_for}|-)",             "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)"                     ]    }geoip {                        source => "http_x_forwarded_for"                        target => "geoip"                        database => "/usr/local/logstash-2.3.4/etc/GeoLiteCity.dat"                        add_field => [ "aaaaaa", "%{[geoip][location][0]}" ]                        add_field => [ "bbbbbb", "%{[geoip][location][1]}" ]                }}output {        stdout {                        codec => rubydebug                } }[elk@Vsftp logstash]$ logstash -f logstash.conf Settings: Default pipeline workers: 4Pipeline main started10.168.255.134 [09/Oct/2016:15:28:52 +0800] "GET / HTTP/1.1" - 200 23388 "" "Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30" 0.001 101.226.125.103{                 "message" => "10.168.255.134 [09/Oct/2016:15:28:52 +0800] /"GET / HTTP/1.1/" - 200 23388 /"/" /"Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30/" 0.001 101.226.125.103",                "@version" => "1",              "@timestamp" => "2017-02-08T01:47:32.656Z",                    "host" => "Vsftp",                "clientip" => "10.168.255.134",                    "time" => "09/Oct/2016:15:28:52 +0800",                    "verb" => "GET",                 "request" => "/",             "httpversion" => "1.1",        "http_status_code" => "200",                   "bytes" => "23388",         "http_user_agent" => "Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30",            "request_time" => "0.001",    "http_x_forwarded_for" => "101.226.125.103",	                   "geoip" => {                      "ip" => "101.226.125.103",           "country_code2" => "CN",           "country_code3" => "CHN",            "country_name" => "China",          "continent_code" => "AS",             "region_name" => "23",               "city_name" => "Shanghai",                "latitude" => 31.045600000000007,               "longitude" => 121.3997,                "timezone" => "Asia/Shanghai",        "real_region_name" => "Shanghai",                "location" => [            [0] 121.3997,            [1] 31.045600000000007        ]    },		                  "aaaaaa" => 121.3997,                  "bbbbbb" => 31.045600000000007}變量值內(nèi)插:[elk@Vsftp logstash]$ cat logstash.conf input {   stdin{}   }filter {    grok {        match =>[              "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request}/?.* HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"(?<http_referer>/S+)/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)",              "message" , "%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"(?<http_referer>/S+)/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)",             "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} (?<http_url>/S+)/s+HTTP/%{NUMBER:httpversion}/"/s+/-/s+%{NUMBER:http_status_code}/s+%{NUMBER:bytes}/s+/"/-/"/s+/"(?<http_user_agent>(/S+))/"/s+(%{BASE16FLOAT:request_time})/s+(%{IPORHOST:http_x_forwarded_for}|-)",             "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)"                     ]    }geoip {                        source => "http_x_forwarded_for"                        target => "geoip"                        database => "/usr/local/logstash-2.3.4/etc/GeoLiteCity.dat"                        add_field => [ "kkkkkkk", "[geoip][location][0]"]                        add_field => [ "hhhhhhh", "[geoip][location][1]" ]                }}output {        stdout {                        codec => rubydebug                } }[elk@Vsftp logstash]$ logstash -f logstash.conf Settings: Default pipeline workers: 4Pipeline main started10.168.255.134 [09/Oct/2016:15:28:52 +0800] "GET / HTTP/1.1" - 200 23388 "" "Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30" 0.001 101.226.125.103{                 "message" => "10.168.255.134 [09/Oct/2016:15:28:52 +0800] /"GET / HTTP/1.1/" - 200 23388 /"/" /"Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30/" 0.001 101.226.125.103",                "@version" => "1",              "@timestamp" => "2017-02-08T01:49:49.034Z",                    "host" => "Vsftp",                "clientip" => "10.168.255.134",                    "time" => "09/Oct/2016:15:28:52 +0800",                    "verb" => "GET",                 "request" => "/",             "httpversion" => "1.1",        "http_status_code" => "200",                   "bytes" => "23388",         "http_user_agent" => "Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30",            "request_time" => "0.001",    "http_x_forwarded_for" => "101.226.125.103",                   "geoip" => {                      "ip" => "101.226.125.103",           "country_code2" => "CN",           "country_code3" => "CHN",            "country_name" => "China",          "continent_code" => "AS",             "region_name" => "23",               "city_name" => "Shanghai",                "latitude" => 31.045600000000007,               "longitude" => 121.3997,                "timezone" => "Asia/Shanghai",        "real_region_name" => "Shanghai",                "location" => [            [0] 121.3997,            [1] 31.045600000000007        ]    },                 "kkkkkkk" => "[geoip][location][0]",                 "hhhhhhh" => "[geoip][location][1]"				 				 	必須使用        add_field => [ "aaaaaa", "%{[geoip][location][0]}" ]                        add_field => [ "bbbbbb", "%{[geoip][location][1]}" ]}
發(fā)表評(píng)論 共有條評(píng)論
用戶名: 密碼:
驗(yàn)證碼: 匿名發(fā)表
主站蜘蛛池模板: 中文字幕第一页久久 | 免费观看www免费观看 | 青青久久av | 免费看片国产 | 免费成人在线观看 | 久久韩剧网 | 欧美黑人xxx| 精品国产黄a∨片高清在线 毛片国产 | 日韩和的一区二区 | 中国女人黄色大片 | 精品视频一区二区在线观看 | 欧美日韩精品一区二区在线观看 | 在线观看免费的av | 亚洲欧美日本在线 | 看免费av | 波多野结衣一区三区 | 一区二区精品在线观看 | 国产免费一区二区 | 久久久久久久久99精品 | 午夜免费高清视频 | 中国特黄视频 | a免费网站 | 2018国产精品 | 涩涩视频在线看 | 国产1区 | 国产一区二区三区高清 | 欧美日韩国产在线观看 | 日本天堂在线观看 | 国产在线日本 | 亚洲欧美中文字幕 | 裸体喂奶一级裸片 | 国产高清av在线一区二区三区 | 爱爱网址 | 伊人久久婷婷 | 夜夜操天天操 | 免费毛片a线观看 | 久久毛片 | 久久久网址 | 久热久| 91一区二区在线 | 欧洲成人午夜免费大片 |