Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- filter {
- if [type] == "apache" {
- grok {
- match => { "message" => "%{COMBINEDAPACHELOG}" }
- tag_on_failure => []
- }
- kv {
- field_split => "&?"
- source => "request"
- target => "kv"
- include_keys => [ "userid", "idfa", "adid", "aid", "ip", "plid", "ho_claim_type", "ho_non_window", "sad",
- "ho_is_assist", "loss_type", "version", "os_version", "existing_user", "conversion_referral",
- "carrier", "agent", "device_brand", "device_model", "region", "devmod", "referrer", "nwt",
- "bidtype", "currency", "lat", "marker", "time", "bundleid", "url", "claim", "platform",
- "nw", "app", "urlloadedinbrowser", "nw_type", "site", "gclid" ]
- }
- geoip {
- source => "clientip"
- target => "geoip"
- database => "/usr/share/GeoIP/GeoIPCity.dat"
- add_field => [ "[geoip][coordinates]", "%{[geoip][longitude]}" ]
- add_field => [ "[geoip][coordinates]", "%{[geoip][latitude]}" ]
- }
- mutate {
- convert => [ "[geoip][coordinates]", "float"]
- }
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement