Log Processing - Exercise
curl localhost:9200/_cluster/health?prettysudo nano /etc/logstash/conf.d/cloud-init.confinput { file { path => "/var/log/cloud-init.log" start_position => "beginning" type => "logs" } } filter { grok { match=> { "message"=>"%{TIMESTAMP_ISO8601:datetime}%{SPACE}%{SPACE}-%{SPACE} (?<module>(?<= - )(.+)(?=\[))(\[)(?<loglevel>(.+)(?=\]))(\]: )%{GREEDYDATA:message}" } } } output { elasticsearch { hosts => ["localhost:9200"] index => "cloud-init" } }sudo service logstash start && sudo tail -f -n 100 /var/log/logstash/logstash-plain.log &curl localhost:9200/cloud-init/_search?pretty=true
Last updated