logstash对nginx日志加上geo地理位置信息
来源:原创
时间:2021-09-03
作者:脚本小站
分类:Linux
官方文档:
elastic.co/guide/en/logstash/7.14/advanced-pipeline.html
配置实例:
input { beats { port => "5044" } } filter { grok { match => { "message" => "%{COMBINEDAPACHELOG}"} } geoip { source => "clientip" database =>"/usr/share/logstash/GeoLite2-City.mmdb" } } output { elasticsearch { hosts => ["http://192.168.199.39:9200"] index => "logstash-nginx-%{+YYYY-MM-dd}" } stdout { codec => rubydebug } }