logstash对nginx日志加上geo地理位置信息
来源:原创
时间:2021-09-03
作者:脚本小站
分类:Linux
官方文档:
elastic.co/guide/en/logstash/7.14/advanced-pipeline.html
配置实例:
input {
beats {
port => "5044"
}
}
filter {
grok {
match => { "message" => "%{COMBINEDAPACHELOG}"}
}
geoip {
source => "clientip"
database =>"/usr/share/logstash/GeoLite2-City.mmdb"
}
}
output {
elasticsearch {
hosts => ["http://192.168.199.39:9200"]
index => "logstash-nginx-%{+YYYY-MM-dd}"
}
stdout { codec => rubydebug }
}