Advertisement
Guest User

Untitled

a guest
Dec 12th, 2019
130
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.89 KB | None | 0 0
  1. filter {
  2. grok {
  3. match => { "message" => ["%{IPORHOST:[nginx][access][remote_ip]} - %{DATA:[nginx][access][user_name]} \[%{HTTPDATE:[nginx][access][time]}\] \"%{WORD:[nginx][access][method]} %{DATA:[nginx][access][url]} HTTP/%{NUMBER:[nginx][access][http_version]}\" %{NUMBER:[nginx][access][response_code]} %{NUMBER:[nginx][access][body_sent][bytes]} \"%{DATA:[nginx][access][referrer]}\" \"%{DATA:[nginx][access][agent]}\""] }
  4. remove_field => "message"
  5. }
  6. mutate {
  7. add_field => { "read_timestamp" => "%{@timestamp}" }
  8. }
  9. date {
  10. match => [ "[nginx][access][time]", "dd/MMM/YYYY:H:m:s Z" ]
  11. remove_field => "[nginx][access][time]"
  12. }
  13. useragent {
  14. source => "[nginx][access][agent]"
  15. target => "[nginx][access][user_agent]"
  16. remove_field => "[nginx][access][agent]"
  17. }
  18. geoip {
  19. source => "[nginx][access][remote_ip]"
  20. }
  21. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement