Logstash之grok字段

#logstash中grok插件的使用
#grok中match插件的使用
grok {
            #提取字段
               match => {
                         "source" => "(\w+/){2}(?.*?)/.*"
                        }
        }
        mutate {
            #重写字段
                rename => {
                        "project" => "proj"
                }
        }
        mutate {
                #去掉没用字段
                remove_field => ["input_type","count","tags","@version","fields","offset","txt","level_name"]
        }

 

你可能感兴趣的:(集群环境)