Guest User

Untitled

a guest
May 17th, 2016
646
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.68 KB | None | 0 0
  1. input {
  2. udp {
  3. port => 514
  4. type => syslog
  5. }
  6. }
  7.  
  8. filter {
  9. if [type] == "syslog" {
  10. grok {
  11. match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
  12. add_field => [ "received_at", "%{@timestamp}" ]
  13. add_field => [ "received_from", "%{host}" ]
  14. }
  15. if [syslog_program] == "RT_FLOW" {
  16. drop { }
  17. }
  18. syslog_pri { }
  19. date {
  20. match => [ "syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]
  21. }
  22. }
  23. }
  24.  
  25. output {
  26. elasticsearch {
  27. hosts => ["localhost:9200"]
  28. index => "logstash-events"
  29. }
  30. }
Advertisement
Add Comment
Please, Sign In to add comment