-
调试
kibana->dev tools->grok debugger 提供了在线调试工具
-
匹配总结
- 匹配nginx日志
# 10.21.135.30 28/Aug/2020:07:56:02 -0400 GET /msp/company_account 200
%{IPORHOST:remote_addr} %{HTTPDATE:time_local} %{WORD:method} %{URIPATHPARAM:request} %{NUMBER:http_version}
- 匹配常规日志
除了grok自带的匹配规则,还可以自定义匹配:(?<字段的名字>正则表达式)
# 2020-08-28 07:56:02,388 INFO [23919][139925308540672] [click_log:record_click:26] click-behavior: [MDR account_management display admin@msp.localhost 1598584677]
click-behavior: \[%{WORD:product} %{WORD:feature} %{WORD:action} (?<user>[a-zA-Z.@\-]*) %{NUMBER:timestamp}\]