码迷,mamicode.com
首页 > 其他好文 > 详细

日志分析(一) 环境准备

时间:2015-05-05 01:19:18      阅读:133      评论:0      收藏:0      [点我收藏+]

标签:

借一张图:
技术分享
搭建版本为:
 
Elasticsearch:1.5.2
Logstash:1.4.2
Kibana:4.0.2
 
Shipper节点配置如下:
input {
file {
path => "/var/log/nginx/*_access.log"
}
}
filter {
if [path] =~ "access" {
mutate { replace => { "type" => "nginx_access" } }
grok {
match => { "message" => "%{IPORHOST:clientip} \[%{HTTPDATE:timestamp}\] \"(?:%{WORD:method} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})\" %{NUMBER:response} (?:%{NUMBER:bytes}|-) %{QS:referrer} %{QS:timeconsumer}" }
}
}
date {
match => [ "timestamp" , "dd/MMM/yyyy:HH:mm:ss Z" ]
}
}
output {
redis {
data_type => "list"
host => “xxx"
password => “xxx"
key => “xxx"
}
}
 
Indexer配置如下:
input {
redis {
data_type => "list"
host => localhost
password => “xxx"
key => “xxx"
}
}
 
output {
elasticsearch {
host => localhost
codec => "json"
}
}

日志分析(一) 环境准备

标签:

原文地址:http://www.cnblogs.com/asfeixue/p/4478018.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!