Logstash输出日志到elasticsearch
Logstash配置文件 [root@test ~]#vimuseTime.conf input { stdin{} } filter { grok { match => { "message" => "\s+(?<API>调用.*(用时|异常)).*useTime=(?<request_time>\d+?)$" } } } output { stdout{ codec => rubydebug } elasticsearch { hosts => ["192.168.81.128:9200"] index => "logstash-%{type}-%{+YYYY.MM.dd}" document_type => "%{type}" workers => 1 template_overwrite => true } } [root@test ~]# 测试对应的日志 [07/29 00:01:17] [INFO] `B10005-15` impl.GzClientServiceImpl...