刚接触elk,想要改下nginx日志的时间格式,按网上的资料这样写,但是没有效果。希望各位指点下
日志时间格式是"time_local" => "21/Dec/2020:01:56:50 -0500"
grok {
patterns_dir => "/usr/local/logstash-7.9.0/patterns"
match => {
"message" => "%{NGINXACCESS}"
}
}
date {
match => ["time_local","yyyy-MM-dd HH:mm:ss Z"]
}
日志时间格式是"time_local" => "21/Dec/2020:01:56:50 -0500"
grok {
patterns_dir => "/usr/local/logstash-7.9.0/patterns"
match => {
"message" => "%{NGINXACCESS}"
}
}
date {
match => ["time_local","yyyy-MM-dd HH:mm:ss Z"]
}
1 个回复
liuxg - Elastic
赞同来自: