elk 分析nginx日志

nginx 日志格式化

log_format logJson '{"client_time": "$time_iso8601", "remote_ip": "$remote_addr", "req_time": "$request_time", "request": "$request","ip": "$http_x_forwarded_for","referer":"$http_referer","http_host","$http_host"}';

Logstash 设置

input {

    file {

        path => "/var/log/nginx/*.log"

        type => "nginx"

        codec => "json"

        start_position => "beginning"

        stat_interval => "3"

    }

}

filter {

  if [type] == "nginx" {

    date {

        match => ["client_time", "yyyy-MM-dd HH:mm:ss"]

    }

  }

}

output {

    if [type] == "nginx" {

        elasticsearch {

            hosts => ["localhost"]

            manage_template => false

            index => "nginx-log-%{+YYYY.MM.dd}"

        }

    }

}
©著作权归作者所有,转载或内容合作请联系作者
【社区内容提示】社区部分内容疑似由AI辅助生成,浏览时请结合常识与多方信息审慎甄别。
平台声明:文章内容(如有图片或视频亦包括在内)由作者上传并发布,文章内容仅代表作者本人观点,简书系信息发布平台,仅提供信息存储服务。

友情链接更多精彩内容