首页 > 其他 > 详细

kibana 分析 nginx

时间:2020-03-06 22:49:16      阅读:91      评论:0      收藏:0      [点我收藏+]

 

input {
        stdin{
        }
}

filter {
        grok {
            match => { "message" => ["%{IPORHOST:[nginx][access][remote_ip]} - %{DATA:[nginx][access][user_name]} \[%{HTTPDATE:[nginx][access][time]}\] \"%{WORD:[nginx][access][method]} %{DATA:[nginx][access][url]} HTTP/%{NUMBER:[nginx][access][http_version]}\" %{NUMBER:[nginx][access][response_code]} %{NUMBER:[nginx][access][body_sent][bytes]} \"%{DATA:[nginx][access][referrer]}\" \"%{DATA:[nginx][access][agent]}\""] }
            remove_field => "message"
        }
        mutate {
            add_field => { "read_timestamp" => "%{@timestamp}" }
        }
        date {
            match => [ "[nginx][access][time]", "dd/MMM/YYYY:H:m:s Z" ]
            remove_field => "[nginx][access][time]"
        }
        useragent {
            source => "[nginx][access][agent]"
            target => "[nginx][access][user_agent]"
            remove_field => "[nginx][access][agent]"
        }
        mutate{
            convert => { "[nginx][access][body_sent][bytes]" => "integer" }
        }

}

output {
  elasticsearch {
    hosts    => [ "localhost" ]
    index    => "logstash-%{+YYYY.MM.dd}"
  }
}

  

时间轴

.es(index=logstash*, timefield=@timestamp, q=nginx.access.response_code:200).label(OK), .es(index=logstash*, timefield=@timestamp, q=nginx.access.response_code:404).label(Page Not Found)

 

kibana 分析 nginx

原文:https://www.cnblogs.com/yzpopulation/p/12431024.html

(0)
(0)
   
举报
评论 一句话评论(0
关于我们 - 联系我们 - 留言反馈 - 联系我们:wmxa8@hotmail.com
© 2014 bubuko.com 版权所有
打开技术之扣,分享程序人生!