Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- input {
- beats {
- port => "5044"
- }
- }
- filter {
- grok {
- match => [ "message", "%{NUMBER:timestamp}\s+%{NUMBER:response_time} %{IPORHOST:src_ip} %{NOTSPACE:squid_request_status}/%{NUMBER:http_status_code} %{NUMBER:transfer_size} %{NOTSPACE:http_method} (%{URIPROTO:url_scheme}://)?(?<url_host>\S+?)(:%{INT:url_port})?(/%{NOTSPACE:url_path})?\s+%{NOTSPACE:client_identity}\s+%{NOTSPACE:peer_code}/%{NOTSPACE:peerhost}\s+%{NOTSPACE:content_type}" ]
- }
- date {
- match => [ "timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]
- }
- }
- output {
- elasticsearch {
- hosts => ["localhost:9200"]
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement