logstash合并有换行符的日志

出现error日志时,有时出现多行信息,如果不处理,logstash会当成多条日志看待.如果你的日志是以时间开关的,请添加如下配置
codec => multiline { 
pattern => "^%{TIMESTAMP_ISO8601}" 
what => "previous" 
negate => true 
}

    file {                                                                                                                                                                                                          
        path => "/data/securityopdata/syncapi/logs/*.log"                                                                                                                                                           
        type => "logfile"                                                                                                                                                                                           
        start_position => "beginning"                                                                                                                                                                               
        #sincedb_path => "/dev/null"                                                                                                                                                                                
        codec => multiline {                                                                                                                                                                                        
            pattern => "^%{TIMESTAMP_ISO8601}"                                                                                                                                                                      
            what => "previous"                                                                                                                                                                                      
            negate => true                                                                                                                                                                                          
        }                                                                                                                                                                                                           
        add_field => {                                                                                                                                                                                              
            HOSTNAME => "郜金丹的空间"                                                                                                                                                                              
            project_name => "syncapi"                                                                                                                                                                               
        }                                                                                                                                                                                                           
    } 

猜你喜欢

转载自blog.csdn.net/nanjizhiyin/article/details/80692339