天天看点

logstash @timestamp 内容替换

conf文件:

input {
   stdin{}
}
filter {
        grok{
           match => ["message","%{HTTPDATE:[@metadata][timestamp]}"]
           }
        date{
                match=>["[@metadata][timestamp]","dd/MMM/yyyy:HH:mm:ss Z"]
        }
}
output{
    stdout{
                codec => "rubydebug"      

输入:

19/Mar/2011:15:36:43 +0100      

效果如下:

继续阅读