Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- input {
- stdin { }
- }
- filter {
- grok {
- match => {
- "message" => '%{IPORHOST:clientip} %{USER:ident} %{USER:auth} \[%{HTTPDATE:timestamp}\] "%{WORD:verb} %{DATA:request} HTTP/%{NUMBER:httpversion}" %{NUMBER:response:int} (?:-|%{NUMBER:bytes:int}) %{QS:referrer} %{QS:agent}'
- }
- }
- date {
- match => [ "timestamp", "dd/MMM/YYYY:HH:mm:ss Z" ]
- locale => en
- }
- geoip {
- source => "clientip"
- }
- useragent {
- source => "agent"
- target => "useragent"
- }
- }
- output {
- elasticsearch {
- hosts => ["localhost:9200"]
- index => "apache_access_logs"
- template => "apache_sizing_2.json"
- template_name => "elk_workshop"
- template_overwrite => true
- }
- }
Add Comment
Please, Sign In to add comment