Please install in this order.
- Download 2.7.9 (64-bit)
- Install with these options:
- Install for all users
- Customize Python 2.7.9:
- Select Add python.exe to Path
input { | |
# file { | |
# path => ["C:/logs/Proj/*/*.log"] | |
# start_position => beginning | |
# } | |
stdin { } | |
} |
Please install in this order.
{ | |
"template" : "logstash-*", | |
"settings" : { | |
"number_of_shards" : 5, | |
"index.refresh_interval" : "5s" | |
}, | |
"mappings" : { | |
"_default_" : { | |
"_all" : {"enabled" : true}, | |
"dynamic_templates" : [ { |
if [type] == "apache_json" { | |
geoip { source => "clientip" } | |
if [useragent] != "" { useragent { source => "useragent" } } | |
if [auth] == "-" { mutate { remove_field => "auth" } } | |
if [ident] == "-" { mutate { remove_field => "ident" } } | |
if [referer] == "-" { mutate { remove_field => "referer" } } | |
} |
30 2 * * * ~/bin/curator.sh &> /dev/null |
output { | |
stdout { debug => true debug_format => "json"} | |
if [type] == 'collectd' { | |
elasticsearch { | |
cluster => "elasticsearch" | |
} | |
} | |
} |
input { stdin {} } | |
filter { | |
grok { | |
match => [ "message", "\[%{RUBY_LOGLEVEL:loglevel}\] %{TIMESTAMP_ISO8601:logdate} %{ISO8601_TIMEZONE:timezone} \[%{NOTSPACE:somefield}\] \[%{IP:ipaddress}\] %{GREEDYDATA:therest}" ] | |
} | |
mutate { | |
gsub => [ "logdate", "\ ", "T" ] | |
replace => { "logdate" => "%{logdate}%{timezone}" } | |
} | |
date { |
input { | |
stdin { | |
type => "weblogic-server" | |
} | |
} | |
filter { | |
### weblogic-server | |
if [type] == "weblogic-server" { | |
multiline { |
buh@BigMini (06:12 PM) [~/GIT/curator/curator] $ curl -XPUT 'http://localhost:9200/logstash-20140710/' | |
{"acknowledged":true} |
$ python test.py --help | |
usage: test.py [-h] [-v] [--host HOST] [--url_prefix URL_PREFIX] [--port PORT] | |
[--ssl] [-t TIMEOUT] [-n] [-D] [--loglevel LOG_LEVEL] | |
[-l LOG_FILE] | |
{allocation,bloom,close,delete,optimize,show_indices,snapshot} | |
... | |
Curator for Elasticsearch indices. See | |
http://github.com/elasticsearch/curator/wiki |