logstash 处理 '[20201212 08:08:08.888][RROR][example][rce]' 数据
[elk@node2 conf]$ cat logstash04.conf input { file { path=>["/home/elk/conf/test.txt"] type=>"system" } }
filter {
mutate { add_field =>["newmessage","%{type}=%{message}"] }
}
grok { match => ["message", ".*?\[(?%{YEAR}%{MONTHNUM}%{MONTHDAY}\s+%{TIME})\]\s*(?(.*))"]
} date { match => ["time","yyyymmdd HH:mm:ss.SSS"] add_field =>{'zjzc' => "helloworld ,from %{syslog_timestamp}"} add_tag => [ "foo_%{str}","tdd_%{syslog_timestamp}" ] }
{ "m