如何编写logstash配置文件以在elk

时间:2018-06-04 12:16:07

标签: elastic-stack logstash-configuration log-analysis

我正在研究ELK堆栈。我仔细检查elk stack已经正确安装。 我正在使用Windows 7 32位& ELK 5.1.2

现在我想将我的数据上传到ELK。所以我使用logstash,首先我必须编写配置文件,但我的配置文件没有错误,我不知道我在将数据上传到logstash时遇到错误。

Could not find log4j2 configuration at path. using the default which log to console.

我认为由于我编写的配置文件导致的这个错误有一些错误。

任何人都告诉我这次我做错了什么

input {
    File {
            path => "C:\elk stack\data\Fr_arp_18.xlsx"
            start_position => "beginning"
    }}filter {
    csv {
        separator => ","
        columns => ["log_id","response_time_in_secs", "response_date_time", "string", "ID", "Version", "data"]
    }
    mutate{ convert => [ "log_id", "integer" ] }
    mutate{ convert => [ "response_time_in_secs", "integer" ] }
    mutate{ convert => [ "ID", "integer" ] }                               }                         output {
    elasticsearch {
        hosts => ["localhost:9200"]
        index => "type"
        manage_template => false
        index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
        document_type => "%{[@metadata][type]}"
    }
    stdout{}                                                                
  }

日志是这样的

27625738,0.1871,01-04-18 0:01,RB03,4400110026,2.3.5,5B009E6E3992
27625746,0.1729,01-04-18 0:01,RV02,4400110011,2.3.5,5A0098F6D6E2
27625751,0.1771,01-04-18 0:02,RB03,4400110011,2.3.5,5A0098F6D6E2
27625768,0.1532,01-04-18 0:03,RV02,4400110014,2.3.5,3F001A959323
27625772,0.1519,01-04-18 0:03,RV02,1100110177,2.3.5,1E008E63E417
27625783,0.2303,01-04-18 0:04,RB03,4400110014,2.3.5,3F001A959323

如果告诉我配置文件指南或教程,那就太棒了。

0 个答案:

没有答案