如何通过logstash将以前的File Extension DATE存储日志文件中的日志读入elasticsearch

时间:2016-08-26 07:39:17

标签: elasticsearch logstash logstash-configuration

前几天的日志存储为文件扩展名DATE格式。 Please refer the pic of the place where logs are stored

请在下面找到我在配置文件中编写的代码。

input { 
file {
path => "D:/elasticsearch-2.3.3/logs/elasticsearch.log.2016-08-24"
start_position => "beginning"
}
}

filter {
date {
match => [ "timestamp" , "dd/MMM/yyyy:HH:mm:ss Z" ]
}
}
output 
{
stdout { codec => rubydebug }
elasticsearch { hosts => ["localhost:9200"] }
}

0 个答案:

没有答案