{"id":1367,"date":"2022-06-29T03:23:20","date_gmt":"2022-06-29T03:23:20","guid":{"rendered":"http:\/\/www.liutianfeng.com\/?p=1367"},"modified":"2023-12-13T08:15:56","modified_gmt":"2023-12-13T08:15:56","slug":"es%e5%a4%87%e4%bb%bd","status":"publish","type":"post","link":"https:\/\/www.liutianfeng.com\/?p=1367","title":{"rendered":"ES\u5907\u4efd&#038;\u6062\u590d"},"content":{"rendered":"<p>1\u3001logstash\u5bfc\u51fa\u6587\u4ef6<\/p>\n<p>\u53c2\u8003\uff1ahttps:\/\/www.cntofu.com\/book\/52\/output\/file.md<\/p>\n<p>\u5907\u4efd\uff1a<\/p>\n<pre class=\"pure-highlightjs\"><code class=\"\">input {\n    elasticsearch {\n        hosts =&gt; [\"http:\/\/192.168.37.174:9200\"]\n        index =&gt; \"yspybd_0002\"    \/\/ \u591a\u4e2a\u7d22\u5f15\u7528,\u9694\u5f00\n        user =&gt; \"es_user\"\n        password =&gt; \"es_passwd_balabalabala\"\n        docinfo =&gt; true\n    }\n}\n\nfilter {\n    mutate {\n        remove_field =&gt; [\"@timestamp\", \"@version\"]\n    }\n}\n\noutput {\n    file {\n        path =&gt; \"\/data\/%{[@metadata][_index]}.json.gz\"\n        gzip =&gt; true  \/\/ gzip\u538b\u7f29\u51cf\u5c11\u7a7a\u95f4\u4f7f\u7528\n    }\n}<\/code><\/pre>\n<p>\u6062\u590d[ from json files ]\uff1a<\/p>\n<pre class=\"pure-highlightjs\"><code class=\"\">input {\n    file {\n        path =&gt; \"\/data\/logstash-7.6.2\/bin\/exec-history-2023-12.json\"\n        sincedb_path =&gt; \"\/dev\/null\"\n        start_position =&gt; beginning  \/\/ \u5fc5\u987b\u52a0\u8fd9\u4e2a\uff0c\u4e0d\u7136\uff0c\u6587\u4ef6\u4e2d\u7684\u6570\u636e\u5f55\u5165\u4e0d\u4e86\uff0clogstash\u9ed8\u8ba4\u662ftail\u6700\u65b0\u7684\u6570\u636e\u5f55\u5165\n        type =&gt; \"json\"  \/\/ \u53ef\u4ee5\u56fa\u5b9a\u52a0\u4e00\u4e2a\u5b57\u6bb5\u5230\u65b0\u7684\u7d22\u5f15\u91cc\u9762\uff0c\u4e0d\u8fc7\u4e00\u822c\u6ca1\u6709\u610f\u4e49\uff0c\u5982\u679c\u505a\u5224\u65ad\uff0c\u6216\u8bb8\u53ef\u4ee5\u52a0\u4e0d\u540c\u7684\n    }\n}\n\nfilter {\n    json {\n        source =&gt; \"message\"  \/\/ source\u662finput\u7684\u5185\u5bb9\uff0c\u5fc5\u987b\u505a\u4e00\u4e2a\u8f6c\u6362\uff0c\u4e0d\u7136\uff0c\u65e7\u7d22\u5f15\u7684\u4e00\u884c\u6570\u636e\u5c31\u4f1a\u53d8\u6210\u65b0\u7d22\u5f15\u7684message\u5b57\u6bb5\n    }\n    mutate {\n        remove_field =&gt; [\"@timestamp\", \"@version\", \"host\"]  \/\/ \u7528\u4e8e\u5220\u9664\u6e90\u6570\u636e\u4e2d\u67d0[\u51e0]\u4e2a\u5b57\u6bb5\n    }\n}\n\noutput {\n    elasticsearch {\n        hosts =&gt; [\"http:\/\/192.168.30.130:9200\"]\n        index =&gt; \"exec-history-2023-12\"\n        user =&gt; \"elastic\"\n        password =&gt; \"uguess\"\n    }\n}<\/code><\/pre>\n<p>liutianfeng.com<\/p>\n<p>\u8f6c\u8f7d\u8bf7\u6ce8\u660e\uff1a<a href=\"https:\/\/www.liutianfeng.com\">liutianfeng.com<\/a> &raquo; <a href=\"https:\/\/www.liutianfeng.com\/?p=1367\">ES\u5907\u4efd&#038;\u6062\u590d<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>1\u3001logstash\u5bfc\u51fa\u6587\u4ef6 \u53c2\u8003\uff1ahttps:\/\/www.cntofu.com\/book\/52\/output [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[52],"tags":[],"_links":{"self":[{"href":"https:\/\/www.liutianfeng.com\/index.php?rest_route=\/wp\/v2\/posts\/1367"}],"collection":[{"href":"https:\/\/www.liutianfeng.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.liutianfeng.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.liutianfeng.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.liutianfeng.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1367"}],"version-history":[{"count":7,"href":"https:\/\/www.liutianfeng.com\/index.php?rest_route=\/wp\/v2\/posts\/1367\/revisions"}],"predecessor-version":[{"id":1806,"href":"https:\/\/www.liutianfeng.com\/index.php?rest_route=\/wp\/v2\/posts\/1367\/revisions\/1806"}],"wp:attachment":[{"href":"https:\/\/www.liutianfeng.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1367"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.liutianfeng.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1367"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.liutianfeng.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1367"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}