logstash不能匹配中文

不要使用自带的匹配,自己写一个就好了

filter{                                                                                                                                                                                                             
    if([project_name] == "syncapi" or [project_name] == "synctool"){                                                                                                                                                
        grok {                                                                                                                                                                                                      
            match => {                                                                                                                                                                                              
                "message" => "%{TIMESTAMP_ISO8601:createTime}\s*\[\s*%{WORD:level}\s*\]\s*\[\s*(?<logger_name>.*?)\s*\]\s*(?<message>.*)"                                                                           
            }                                                                                                                                                                                                       
            overwrite => ["message"]                                                                                                                                                                                
        }                                                                                                                                                                                                           
    }                                                                                                                                                                                                               
    date {                                                                                                                                                                                                          
        match => ["createTime","yyyy-MM-dd HH:mm:ss","UNIX"]                                                                                                                                                        
        #target => "asdfasf"                                                                                                                                                                                        
    }                                                                                                                                                                                                               
} 

猜你喜欢

转载自blog.csdn.net/nanjizhiyin/article/details/80692375