官术网_书友最值得收藏!

Logstash

Logstash is a data pipeline that can take data input from various sources, filter it, and output it to various sources; these sources can be files, Kafka, or databases. Logstash is a very important tool in Elastic Stack as it's primarily used to pull data from various sources and push it to Elasticsearch; from there, Kibana can use that data for analysis or visualization. We can take any type of data using Logstash, such as structured or unstructured data , which comes from various sources, such as the internet. The data can be transformed using Logstash's filter option, which has different plugins to play with different sets of data. For example, if we get an IP address in our data, the GeoIP plugin can add geolocation using that IP address, and in the output, we can get additional information of geolocation, which can then be used in Kibana to plot a map.

The following expression shows us an example of a Logstash configuration file:

input 
{
file
{
path => "/var/log/apache2/access.log"
}
}
filter
{
grok
{
match => {message => "%{COMBINEDAPACHELOG}"}
}
}
output
{
elasticsearch
{
hosts => "localhost"
}
}

In the preceding expression, we have three sections: input, filter, and output. In the input section, we're reading the Apache access log file data. The filter section is there to extract Apache access log data in different fields, using the grok filter option. The output section is quite straightforward as it's pushing the data to the local Elasticsearch cluster. We can configure the input and output sections to read or write from or to different sources, whereas we can apply different plugins to transform the input data; for example, we can mutate a field, transform a field value, or add geolocation from an IP address using the filter option.


Grok is a tool that we can use to generate structured and queryable data by parsing unstructured data.
主站蜘蛛池模板: 曲阜市| 怀集县| 玉树县| 宁南县| 额敏县| 辽源市| 永城市| 克什克腾旗| 金乡县| 潜江市| 军事| 宁武县| 普兰店市| 东宁县| 福建省| 务川| 玉门市| 巧家县| 恩施市| 东平县| 乌海市| 固阳县| 郓城县| 兴海县| 永昌县| 防城港市| 濮阳县| 乌兰浩特市| 重庆市| 盱眙县| 湟源县| 金寨县| 云梦县| 曲松县| 昭苏县| 苏尼特左旗| 汶上县| 辛集市| 济南市| 攀枝花市| 彰武县|