天天看點

logstash @timestamp 内容替換

conf檔案:

input {
   stdin{}
}
filter {
        grok{
           match => ["message","%{HTTPDATE:[@metadata][timestamp]}"]
           }
        date{
                match=>["[@metadata][timestamp]","dd/MMM/yyyy:HH:mm:ss Z"]
        }
}
output{
    stdout{
                codec => "rubydebug"      

輸入:

19/Mar/2011:15:36:43 +0100      

效果如下:

繼續閱讀