在Kibana中查看Logstash结果取决于日志文件夹

时间:2019-03-04 12:02:47

标签: elasticsearch logstash logstash-configuration kibana-6 logstash-file

我是Logstash和Kibana的新用户 我尝试查看我的日志在kibana中分离,具体取决于那里的文件夹 我运行logstash服务包含我的管道,如下所示

input {
 file {
  { type => "STAGE-LOG-ADMIN"
    path => "C:\Users\elkstask-master\stage-logs\admin/*.log"},
 tags => ["ADMIN"] }
 file {
  { type => "STAGE-LOG-MS02" 
    path => "C:\Users\elkstask-master\stage-logs\ms02/*.log"},
 tags => ["MS02"] }
 file {
  { type => "custom" 
    path => "C:\Users\elkstask-master/*.log"}, 
 tags => ["custom"]
 }
}

output {
 if "ADMIN" in [tags] {
   elasticsearch {
         hosts => "localhost:9200"
         index => "ADMIN"
         document_type => "ADMIN-%{+YYYY.MM.dd}"
        }
    } 
    if "MS02" in [tags] {
        elasticsearch {
            hosts => "localhost:9200"
            index => "MS02"
            document_type => "MS02-%{+YYYY.MM.dd}"
        }
    }
    if "custom" in [tags] {
        elasticsearch {
            hosts => "localhost:9200"
            index => "custom"
            document_type => "custom-%{+YYYY.MM.dd}"
        }
     }
 }

但是在kibana中的输出显示了我所有的日志,如何显示它被文件夹分开

0 个答案:

没有答案