logstash收集Nginx日志,轉換為JSON格式


Nginx日志處理為JSON格式,並放置在http區塊:

 1  log_format  json  '{"@timestamp":"$time_iso8601",'
 2                       '"@version":"1",'
 3                       '"client":"$remote_addr",'
 4                       '"url":"$uri",'
 5                       '"status":"$status",'
 6                       '"domain":"$host",'
 7                       '"host":"$server_addr",'
 8                       '"size":"$body_bytes_sent",'
 9                       '"responsentime":"$request_time",'
10                       '"referer":"$http_referer",'
11                       '"useragent":"$http_user_agent"'
12                        '}';
13 access_log  logs/access_json.log  json;
Nginx日志格式

 

logstash配置文件:

 1 input {
 2        file {
 3       path =>"/usr/local/nginx/logs/access_json.log"
 4       codec =>"json"
 5       start_position => "beginning"
 6 
 7         }
 8 }
 9 
10 filter{
11    json {
12                 source => "message"
13                 skip_on_invalid_json => true
14                 }
15 }
16 output{
17 
18 
19       elasticsearch {
20        hosts =>["172.16.3.160:9200"]
21        index => "logstash-zabbix-nginx-log-%{+YYYY.MM.dd}"
22 
23            }
24 }
logstash配置文件

 


免責聲明!

本站轉載的文章為個人學習借鑒使用,本站對版權不負任何法律責任。如果侵犯了您的隱私權益,請聯系本站郵箱yoyou2525@163.com刪除。



 
粵ICP備18138465號   © 2018-2025 CODEPRJ.COM