- Kibana 7 Quick Start Guide
- Anurag Srivastava
- 322字
- 2021-07-02 13:55:37
Logstash
Logstash is a data pipeline that can take data input from various sources, filter it, and output it to various sources; these sources can be files, Kafka, or databases. Logstash is a very important tool in Elastic Stack as it's primarily used to pull data from various sources and push it to Elasticsearch; from there, Kibana can use that data for analysis or visualization. We can take any type of data using Logstash, such as structured or unstructured data , which comes from various sources, such as the internet. The data can be transformed using Logstash's filter option, which has different plugins to play with different sets of data. For example, if we get an IP address in our data, the GeoIP plugin can add geolocation using that IP address, and in the output, we can get additional information of geolocation, which can then be used in Kibana to plot a map.
The following expression shows us an example of a Logstash configuration file:
input
{
file
{
path => "/var/log/apache2/access.log"
}
}
filter
{
grok
{
match => {message => "%{COMBINEDAPACHELOG}"}
}
}
output
{
elasticsearch
{
hosts => "localhost"
}
}
In the preceding expression, we have three sections: input, filter, and output. In the input section, we're reading the Apache access log file data. The filter section is there to extract Apache access log data in different fields, using the grok filter option. The output section is quite straightforward as it's pushing the data to the local Elasticsearch cluster. We can configure the input and output sections to read or write from or to different sources, whereas we can apply different plugins to transform the input data; for example, we can mutate a field, transform a field value, or add geolocation from an IP address using the filter option.
Grok is a tool that we can use to generate structured and queryable data by parsing unstructured data.
- 工業(yè)機(jī)器人虛擬仿真實(shí)例教程:KUKA.Sim Pro(全彩版)
- Mastering Mesos
- 高效能辦公必修課:Word圖文處理
- 平面設(shè)計(jì)初步
- 21小時(shí)學(xué)通AutoCAD
- 會(huì)聲會(huì)影X5視頻剪輯高手速成
- 基于單片機(jī)的嵌入式工程開發(fā)詳解
- 影視后期編輯與合成
- Windows Server 2003系統(tǒng)安全管理
- 在實(shí)戰(zhàn)中成長(zhǎng):C++開發(fā)之路
- ASP.NET 2.0 Web開發(fā)入門指南
- Mastering Exploratory Analysis with pandas
- 電腦故障排除與維護(hù)終極技巧金典
- Learning iOS 8 for Enterprise
- 工業(yè)機(jī)器人應(yīng)用系統(tǒng)三維建模