亚洲香蕉成人av网站在线观看_欧美精品成人91久久久久久久_久久久久久久久久久亚洲_热久久视久久精品18亚洲精品_国产精自产拍久久久久久_亚洲色图国产精品_91精品国产网站_中文字幕欧美日韩精品_国产精品久久久久久亚洲调教_国产精品久久一区_性夜试看影院91社区_97在线观看视频国产_68精品久久久久久欧美_欧美精品在线观看_国产精品一区二区久久精品_欧美老女人bb

首頁 > 學院 > 操作系統 > 正文

logstash 字段引用

2024-06-28 16:01:14
字體:
來源:轉載
供稿:網友
字段引用:10.168.255.134 [09/Oct/2016:15:28:52 +0800] "GET / HTTP/1.1" - 200 23388 "" "Mozilla/5.0 (linux; U; Android 4.4.4; zh-cn; MX4 PRo Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30" 0.001 101.226.125.103[elk@Vsftp logstash]$ cat logstash.conf input {   stdin{}   }filter {    grok {        match =>[              "message","%{ipORHOST:clientip} /[%{HTTPDATE:time}/] /"%{Word:verb} %{URIPATHPARAM:request}/?.* HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"(?<http_referer>/S+)/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)",              "message" , "%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"(?<http_referer>/S+)/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)",             "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} (?<http_url>/S+)/s+HTTP/%{NUMBER:httpversion}/"/s+/-/s+%{NUMBER:http_status_code}/s+%{NUMBER:bytes}/s+/"/-/"/s+/"(?<http_user_agent>(/S+))/"/s+(%{BASE16FLOAT:request_time})/s+(%{IPORHOST:http_x_forwarded_for}|-)",             "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)"                     ]    }}output {        stdout {                        codec => rubydebug                } }[elk@Vsftp logstash]$ logstash -f logstash.conf Settings: Default pipeline workers: 4Pipeline main started10.168.255.134 [09/Oct/2016:15:28:52 +0800] "GET / HTTP/1.1" - 200 23388 "" "Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30" 0.001 101.226.125.103{                 "message" => "10.168.255.134 [09/Oct/2016:15:28:52 +0800] /"GET / HTTP/1.1/" - 200 23388 /"/" /"Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30/" 0.001 101.226.125.103",                "@version" => "1",              "@timestamp" => "2017-02-08T01:39:50.650Z",                    "host" => "Vsftp",                "clientip" => "10.168.255.134",                    "time" => "09/Oct/2016:15:28:52 +0800",                    "verb" => "GET",                 "request" => "/",             "httpversion" => "1.1",        "http_status_code" => "200",                   "bytes" => "23388",         "http_user_agent" => "Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30",            "request_time" => "0.001",    "http_x_forwarded_for" => "101.226.125.103"}[elk@Vsftp logstash]$ cat logstash.conf input {   stdin{}   }filter {    grok {        match =>[              "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request}/?.* HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"(?<http_referer>/S+)/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)",              "message" , "%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"(?<http_referer>/S+)/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)",             "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} (?<http_url>/S+)/s+HTTP/%{NUMBER:httpversion}/"/s+/-/s+%{NUMBER:http_status_code}/s+%{NUMBER:bytes}/s+/"/-/"/s+/"(?<http_user_agent>(/S+))/"/s+(%{BASE16FLOAT:request_time})/s+(%{IPORHOST:http_x_forwarded_for}|-)",             "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)"                     ]    }geoip {                        source => "http_x_forwarded_for"                        target => "geoip"                        database => "/usr/local/logstash-2.3.4/etc/GeoLiteCity.dat"                        add_field => [ "[geoip][coordinates]", "%{[geoip][longitude]}" ]                        add_field => [ "[geoip][coordinates]", "%{[geoip][latitude]}"  ]                }}output {        stdout {                        codec => rubydebug                } }[elk@Vsftp logstash]$ logstash -f logstash.conf Settings: Default pipeline workers: 4Pipeline main started10.168.255.134 [09/Oct/2016:15:28:52 +0800] "GET / HTTP/1.1" - 200 23388 "" "Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30" 0.001 101.226.125.103{                 "message" => "10.168.255.134 [09/Oct/2016:15:28:52 +0800] /"GET / HTTP/1.1/" - 200 23388 /"/" /"Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30/" 0.001 101.226.125.103",                "@version" => "1",              "@timestamp" => "2017-02-08T01:42:33.645Z",                    "host" => "Vsftp",                "clientip" => "10.168.255.134",                    "time" => "09/Oct/2016:15:28:52 +0800",                    "verb" => "GET",                 "request" => "/",             "httpversion" => "1.1",        "http_status_code" => "200",                   "bytes" => "23388",         "http_user_agent" => "Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30",            "request_time" => "0.001",    "http_x_forwarded_for" => "101.226.125.103",                   "geoip" => {                      "ip" => "101.226.125.103",           "country_code2" => "CN",           "country_code3" => "CHN",            "country_name" => "China",          "continent_code" => "AS",             "region_name" => "23",               "city_name" => "Shanghai",                "latitude" => 31.045600000000007,               "longitude" => 121.3997,                "timezone" => "Asia/Shanghai",        "real_region_name" => "Shanghai",                "location" => [            [0] 121.3997,            [1] 31.045600000000007        ],             "coordinates" => [            [0] 121.3997,            [1] 31.045600000000007        ]    }}字段引用字段引用是Logstash::Event 對象的屬性,我們之前提過事件就像一個哈希一樣,所以你可以想象字段就像一個鍵值對如果你想在Logstash 配置中使用字段的值,只需把字段的名字寫在中括號[]里就行了,這就叫字段引用[elk@Vsftp logstash]$ cat logstash.conf input {   stdin{}   }filter {    grok {        match =>[              "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request}/?.* HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"(?<http_referer>/S+)/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)",              "message" , "%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"(?<http_referer>/S+)/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)",             "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} (?<http_url>/S+)/s+HTTP/%{NUMBER:httpversion}/"/s+/-/s+%{NUMBER:http_status_code}/s+%{NUMBER:bytes}/s+/"/-/"/s+/"(?<http_user_agent>(/S+))/"/s+(%{BASE16FLOAT:request_time})/s+(%{IPORHOST:http_x_forwarded_for}|-)",             "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)"                     ]    }geoip {                        source => "http_x_forwarded_for"                        target => "geoip"                        database => "/usr/local/logstash-2.3.4/etc/GeoLiteCity.dat"                        add_field => [ "aaaaaa", "%{[geoip][location][0]}" ]                        add_field => [ "bbbbbb", "%{[geoip][location][1]}" ]                }}output {        stdout {                        codec => rubydebug                } }[elk@Vsftp logstash]$ logstash -f logstash.conf Settings: Default pipeline workers: 4Pipeline main started10.168.255.134 [09/Oct/2016:15:28:52 +0800] "GET / HTTP/1.1" - 200 23388 "" "Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30" 0.001 101.226.125.103{                 "message" => "10.168.255.134 [09/Oct/2016:15:28:52 +0800] /"GET / HTTP/1.1/" - 200 23388 /"/" /"Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30/" 0.001 101.226.125.103",                "@version" => "1",              "@timestamp" => "2017-02-08T01:47:32.656Z",                    "host" => "Vsftp",                "clientip" => "10.168.255.134",                    "time" => "09/Oct/2016:15:28:52 +0800",                    "verb" => "GET",                 "request" => "/",             "httpversion" => "1.1",        "http_status_code" => "200",                   "bytes" => "23388",         "http_user_agent" => "Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30",            "request_time" => "0.001",    "http_x_forwarded_for" => "101.226.125.103",	                   "geoip" => {                      "ip" => "101.226.125.103",           "country_code2" => "CN",           "country_code3" => "CHN",            "country_name" => "China",          "continent_code" => "AS",             "region_name" => "23",               "city_name" => "Shanghai",                "latitude" => 31.045600000000007,               "longitude" => 121.3997,                "timezone" => "Asia/Shanghai",        "real_region_name" => "Shanghai",                "location" => [            [0] 121.3997,            [1] 31.045600000000007        ]    },		                  "aaaaaa" => 121.3997,                  "bbbbbb" => 31.045600000000007}變量值內插:[elk@Vsftp logstash]$ cat logstash.conf input {   stdin{}   }filter {    grok {        match =>[              "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request}/?.* HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"(?<http_referer>/S+)/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)",              "message" , "%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"(?<http_referer>/S+)/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)",             "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} (?<http_url>/S+)/s+HTTP/%{NUMBER:httpversion}/"/s+/-/s+%{NUMBER:http_status_code}/s+%{NUMBER:bytes}/s+/"/-/"/s+/"(?<http_user_agent>(/S+))/"/s+(%{BASE16FLOAT:request_time})/s+(%{IPORHOST:http_x_forwarded_for}|-)",             "message","%{IPORHOST:clientip} /[%{HTTPDATE:time}/] /"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}/" /- %{NUMBER:http_status_code} %{NUMBER:bytes} /"/" /"(?<http_user_agent>(/S+/s+)*/S+)/" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)"                     ]    }geoip {                        source => "http_x_forwarded_for"                        target => "geoip"                        database => "/usr/local/logstash-2.3.4/etc/GeoLiteCity.dat"                        add_field => [ "kkkkkkk", "[geoip][location][0]"]                        add_field => [ "hhhhhhh", "[geoip][location][1]" ]                }}output {        stdout {                        codec => rubydebug                } }[elk@Vsftp logstash]$ logstash -f logstash.conf Settings: Default pipeline workers: 4Pipeline main started10.168.255.134 [09/Oct/2016:15:28:52 +0800] "GET / HTTP/1.1" - 200 23388 "" "Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30" 0.001 101.226.125.103{                 "message" => "10.168.255.134 [09/Oct/2016:15:28:52 +0800] /"GET / HTTP/1.1/" - 200 23388 /"/" /"Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30/" 0.001 101.226.125.103",                "@version" => "1",              "@timestamp" => "2017-02-08T01:49:49.034Z",                    "host" => "Vsftp",                "clientip" => "10.168.255.134",                    "time" => "09/Oct/2016:15:28:52 +0800",                    "verb" => "GET",                 "request" => "/",             "httpversion" => "1.1",        "http_status_code" => "200",                   "bytes" => "23388",         "http_user_agent" => "Mozilla/5.0 (Linux; U; Android 4.4.4; zh-cn; MX4 Pro Build/KTU84P) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30",            "request_time" => "0.001",    "http_x_forwarded_for" => "101.226.125.103",                   "geoip" => {                      "ip" => "101.226.125.103",           "country_code2" => "CN",           "country_code3" => "CHN",            "country_name" => "China",          "continent_code" => "AS",             "region_name" => "23",               "city_name" => "Shanghai",                "latitude" => 31.045600000000007,               "longitude" => 121.3997,                "timezone" => "Asia/Shanghai",        "real_region_name" => "Shanghai",                "location" => [            [0] 121.3997,            [1] 31.045600000000007        ]    },                 "kkkkkkk" => "[geoip][location][0]",                 "hhhhhhh" => "[geoip][location][1]"				 				 	必須使用        add_field => [ "aaaaaa", "%{[geoip][location][0]}" ]                        add_field => [ "bbbbbb", "%{[geoip][location][1]}" ]}
發表評論 共有條評論
用戶名: 密碼:
驗證碼: 匿名發表
亚洲香蕉成人av网站在线观看_欧美精品成人91久久久久久久_久久久久久久久久久亚洲_热久久视久久精品18亚洲精品_国产精自产拍久久久久久_亚洲色图国产精品_91精品国产网站_中文字幕欧美日韩精品_国产精品久久久久久亚洲调教_国产精品久久一区_性夜试看影院91社区_97在线观看视频国产_68精品久久久久久欧美_欧美精品在线观看_国产精品一区二区久久精品_欧美老女人bb
亚洲精品二三区| 在线视频欧美日韩| 91天堂在线观看| 欧美日韩国产丝袜美女| 亚洲黄色有码视频| 狠狠躁夜夜躁久久躁别揉| 精品国产乱码久久久久久婷婷| 久久久久国产一区二区三区| 亚洲成人av片| 91黑丝在线观看| 亚洲性av在线| 亚洲精品女av网站| 红桃视频成人在线观看| 91成人在线观看国产| 成人国产精品日本在线| 北条麻妃一区二区三区中文字幕| 欧美一二三视频| 久久视频这里只有精品| 欧美日韩美女在线观看| 欧美高清不卡在线| 欧美电影免费观看大全| 欧美天天综合色影久久精品| 全色精品综合影院| 欧美一级黑人aaaaaaa做受| 日韩美女免费观看| 日韩电影中文字幕一区| 精品呦交小u女在线| 亚洲天堂影视av| 欧美理论电影在线播放| 欧美在线视频网| 国产极品jizzhd欧美| 岛国视频午夜一区免费在线观看| 成人av电影天堂| 国产欧美日韩中文字幕| 欧美高清在线视频观看不卡| 成人有码在线播放| 亚洲va久久久噜噜噜久久天堂| 欧美精品videos| zzjj国产精品一区二区| 成人激情电影一区二区| 亚洲少妇激情视频| 精品久久久久久久久久国产| 日本亚洲欧洲色α| 国产精品免费视频久久久| 日韩av影片在线观看| 操日韩av在线电影| 国内精品国产三级国产在线专| 久久久噜噜噜久久| 国产精品爱啪在线线免费观看| 精品久久久久久中文字幕一区奶水| 国产在线拍偷自揄拍精品| 亚洲自拍偷拍视频| 亚洲国产精品久久久久秋霞蜜臀| 91欧美激情另类亚洲| 久久精品国产免费观看| 精品中文视频在线| 国产精品无码专区在线观看| 国产精品视频不卡| 国产偷亚洲偷欧美偷精品| 日韩视频一区在线| 日韩在线观看精品| 啊v视频在线一区二区三区| 夜色77av精品影院| 亚洲va久久久噜噜噜久久天堂| 欧美性极品少妇精品网站| 亚洲一区二区国产| 亚洲欧洲午夜一线一品| 久久免费视频网站| 国产精品日韩一区| 在线播放国产一区二区三区| 这里精品视频免费| 日韩免费黄色av| 久久精品国产精品亚洲| 亚洲国产中文字幕在线观看| 亚洲自拍偷拍福利| 国产精品一香蕉国产线看观看| 国产精品成人播放| 成人97在线观看视频| 欧美性视频精品| 欧美精品成人91久久久久久久| 2020欧美日韩在线视频| 国产日韩欧美影视| 97视频在线观看免费高清完整版在线观看| 日韩精品视频中文在线观看| 亚洲福利视频专区| 亚洲一区二区三区四区视频| 在线视频中文亚洲| 国产精品久久久久99| 国产91在线播放九色快色| 久久精品国产一区二区三区| 亚洲一区二区中文字幕| 欧美性极品少妇精品网站| 亚洲男女自偷自拍图片另类| 91av国产在线| 欧美激情在线狂野欧美精品| 欧美性猛交xxxx乱大交3| 欧美在线免费观看| 91香蕉电影院| 亚洲精品动漫久久久久| 亚洲精品小视频在线观看| 精品香蕉在线观看视频一| 日韩在线激情视频| 亚洲第一偷拍网| 亚洲精品国产品国语在线| 亚洲人成绝费网站色www| 精品福利一区二区| 久久99精品视频一区97| 亚洲欧美国产制服动漫| 日韩精品一二三四区| 国产精品69精品一区二区三区| 日韩高清欧美高清| 国内外成人免费激情在线视频网站| 51ⅴ精品国产91久久久久久| 亚洲97在线观看| 成人福利在线观看| 欧美高清电影在线看| 色偷偷亚洲男人天堂| 欧美激情性做爰免费视频| 欧美老女人性视频| 国产欧美日韩中文| 日本久久久久久久| 国产91精品网站| 色综合五月天导航| 538国产精品一区二区在线| 亚洲国产毛片完整版| 国产精品美女久久久免费| 国产激情久久久| 91中文字幕一区| 国产成人亚洲精品| 91探花福利精品国产自产在线| 欧美日韩ab片| 亚洲开心激情网| 久久久国产精彩视频美女艺术照福利| 国产精品无av码在线观看| 国产小视频91| 最好看的2019年中文视频| 日韩中文字幕精品| 亚洲一区二区久久久久久| 国产日韩在线看| 亚洲精品av在线播放| 亚洲的天堂在线中文字幕| 日本精品久久电影| 欧美视频免费在线观看| 亚洲高清久久网| 欧美国产亚洲精品久久久8v| 成人久久久久爱| 久久国产精品久久久久久| 美女性感视频久久久| 亚洲精品720p| 欧美性猛交xxxx乱大交极品| 色哟哟网站入口亚洲精品| 91丨九色丨国产在线| 久久久久久中文字幕| 日本精品久久中文字幕佐佐木| 欧美精品第一页在线播放| 久久精品久久久久久国产 免费| 久久综合伊人77777尤物| 亚洲精品久久久一区二区三区| 日韩欧美在线免费| 成人精品在线观看| 亚洲美女福利视频网站| 欧美一级高清免费| 日韩毛片在线看| 欧美在线视频观看|