Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- filter {
- if [type] == "elb-log" {
- grok {
- match => [ "message", "%{TIMESTAMP_ISO8601:timestamp} %{NOTSPACE:elb_name} %{IP:elb_client_ip}:%{INT:elb_client_port} %{IP:elb_backend_ip}:%{INT:elb_backend_port} %{BASE16FLOAT:request_processing_time} %{BASE16FLOAT:backend_processing_time} %{BASE16FLOAT:response_processing_time} %{UUID:elb_status_code} %{UUID:backend_status_code} %{INT:elb_received_bytes} %{INT:elb_sent_bytes}\ %{GREEDYDATA:data}" ]
- }
- date {
- match => ["timestamp","yyyy-MM-dd HH:mm:ss,SSS"]
- remove_field => ["timestamp"]
- }
- mutate {
- update => {
- "type" => "classic-elb-log"
- }
- }
- }
- }
Add Comment
Please, Sign In to add comment