2021-01-04 ELK's first test kabala grok-debug tool test built-in grok regular

The first test can use grok built-in regular:

Use kabala built-in grok test link:

http://ip:5601/app/kibana#/dev_tools/grokdebugger

Log:

[2021-01-04 15:54:14.707][INFO][cn.com.XXXX.mms.component.ons.consumer.NWMessageListener]XXXX日志写入路径:/home/tomcat8/jsonData/log/nuanwa/2021/1/policyIssue/826202101110100026854_3936826_receive.txt

grok filter rules:

\[%{DATA:timestamp}\]\[%{WORD:verb}\]\[%{URIPROTO:request}\].*\:%{URIPATHPARAM:mes}

effect:

{
  "request": "cn.com.XXXX.mms.component.ons.consumer.NWMessageListener",
  "verb": "INFO",
  "mes": "/home/tomcat8/jsonData/log/nuanwa/2021/1/policyIssue/826202101110100026854_3936826_receive.txt",
  "timestamp": "2021-01-04 15:54:14.707"
}

 

Guess you like

Origin blog.csdn.net/yuezhilangniao/article/details/112187839