日志范例:


{"me":"Confirm","es":"2013-11-20 11:40:35.039","et":"2013-11-20 11:40:35.086","wt":"0","st":"0","ds":"errCode=-504,key=8d0501302c0b530d9d8d8b94ac987b24,deviceId=100002,code=620236918034,type=1,storeId=100002,activityId=100001,useAmount=1,mobile=13000000000,requestSerialNumber=131120121437124542,msg=同步地址为空!"}


配置文件:


input {
    tcp {
        port => 3335
        codec => json_lines {charset => ["UTF-8"]}
    }
}
output {
    elasticsearch { embedded => true }
}



kibana中日志效果

logstash匹配切割json格式日志_第1张图片