Advertisement
Guest User

Untitled

a guest
Feb 24th, 2017
81
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.45 KB | None | 0 0
  1. input {
  2. file {
  3. path => "C:elasticsearch-2.4.1sir.log"
  4. start_position => "beginning"
  5. }
  6. }
  7.  
  8. filter {
  9. grok {
  10. match => [ "message", "[%{TIMESTAMP_ISO8601:TIMESTAMP}][%{LOGLEVEL:LEVEL}%{SPACE}][%{DATA:QUERY}]%{SPACE}[%{DATA:QUERY1}]%{SPACE}[%{DATA:INDEX-NAME}][%{DATA:SHARD}]%{SPACE}took[%{DATA:TOOK}],%{SPACE}took_millis[%{DATA:TOOKM}], types[%{DATA:types}], stats[%{DATA:stats}], search_type[%{DATA:search_type}], total_shards[%{NUMBER:total_shards}], source[%{DATA:source_query}], extra_source[%{DATA:extra_source}],"]
  11. }
  12. }
  13. mutate {
  14. gsub => [
  15. *i am not sure which line i have to give here*
  16. ]
  17. }
  18. }
  19. output {
  20. csv {
  21. fields => ["extra_source"]
  22. path => "C:logstashlogstash-2.4.0binsource.csv"
  23.  
  24. }
  25. stdout { codec => rubydebug }
  26.  
  27. }
  28.  
  29. [2017-02-22 14:29:04,859][TRACE][index.search.slowlog.fetch] [Powderkeg] [picase][1] took[1.3ms], took_millis[1], types[], stats[], search_type[QUERY_THEN_FETCH], total_shards[5], source[{"query":{"filtered":{"query":{"match":{"independece":"{india} {15} {07} {15}"}},"filter":{"range":{"@timestamp":{"gt":"now-1d"}}}}},"aggs":{"group_by_BatchId":{"terms":{"field":"fields.regular"},"aggs":{"byHours":{"terms":{"script":"doc['created'].date.hourOfDay().getAsText()","order":{"avg_TimeTaken":"asc"}},"aggs":{"avg_TimeTaken":{"avg":{"field":"fields.inra"}}}}}}},"_source":["fields.sara","fields.sierra","mercedes"]}], extra_source[],
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement