使用Apache的access_log和error_log的logstash

时间:2018-07-08 11:26:54

标签: apache elasticsearch logstash

我正在使用apache的access_log和error_log,但是logstash不会创建索引,我认为apache日志中的问题,这是我的输出

logstash_1       | [2018-07-08T11:18:53,189][INFO ]
[logstash.outputs.elasticsearch] Using mapping template from {:path=>nil}
logstash_1       | [2018-07-08T11:18:53,274][INFO ][logstash.outputs.elasticsearch] Attempting to install template {:manage_template=>{"template"=>"logstash-*", "version"=>60001, "settings"=>{"index.refresh_interval"=>"5s"}, "mappings"=>{"_default_"=>{"dynamic_templates"=>[{"message_field"=>{"path_match"=>"message", "match_mapping_type"=>"string", "mapping"=>{"type"=>"text", "norms"=>false}}}, {"string_fields"=>{"match"=>"*", "match_mapping_type"=>"string", "mapping"=>{"type"=>"text", "norms"=>false, "fields"=>{"keyword"=>{"type"=>"keyword", "ignore_above"=>256}}}}}], "properties"=>{"@timestamp"=>{"type"=>"date"}, "@version"=>{"type"=>"keyword"}, "geoip"=>{"dynamic"=>true, "properties"=>{"ip"=>{"type"=>"ip"}, "location"=>{"type"=>"geo_point"}, "latitude"=>{"type"=>"half_float"}, "longitude"=>{"type"=>"half_float"}}}}}}}}
logstash_1       | [2018-07-08T11:18:53,422][INFO ][logstash.outputs.elasticsearch] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["//elasticsearch"]}
logstash_1       | [2018-07-08T11:18:54,886][INFO ][logstash.inputs.beats    ] Beats inputs: Starting input listener {:address=>"0.0.0.0:5044"}
logstash_1       | [2018-07-08T11:18:55,073][INFO ][logstash.pipeline        ] Pipeline started successfully {:pipeline_id=>"main", :thread=>"#<Thread:0x2cb61e2e run>"}
logstash_1       | [2018-07-08T11:18:55,299][INFO ][org.logstash.beats.Server] Starting server on port: 5044
logstash_1       | [2018-07-08T11:18:55,519][INFO ][logstash.agent           ] Pipelines running {:count=>1, :pipelines=>["main"]}

我该怎么办?有帮助吗?

0 个答案:

没有答案