1、Packetbeat默认配置不能抓取到域名和cookie,如何才能抓取到cookie,求大牛指导。
{
"@timestamp": "2017-07-23T06:57:10.919Z",
"beat": {
"hostname": "xx",
"name": "xx",
"version": "5.5.0"
},
"bytes_in": 618,
"bytes_out": 533,
"client_ip": "xx",
"client_port": 24039,
"client_proc": "",
"client_server": "",
"direction": "out",
"http": {
"request": {
"headers": {
"content-length": 122,
"content-type": "application/x-www-form-urlencoded"
},
"params": "clientCityName=%E5%8C%97%E4%BA%AC\u0026clientOSName=Win\u0026clientProvinceName=%E5%8C%97%E4%BA%AC\u0026dataType=00\u0026platformStr=01_01_0000_000000_%E9%A6%96%E9%A1%B5\u0026referer="
},
"response": {
"code": 200,
"headers": {
"content-length": 0
},
"phrase": "OK"
}
},
"ip": "101.37.42.237",
"method": "POST",
"path": "/userBehaviorRecord_sendUserBeHaviorData.action",
"port": 80,
"proc": "",
"query": "POST /userBehaviorRecord_sendUserBeHaviorData.action",
"responsetime": 148,
"server": "",
"status": "OK",
"type": "http"
}
{
"@timestamp": "2017-07-23T06:57:10.919Z",
"beat": {
"hostname": "xx",
"name": "xx",
"version": "5.5.0"
},
"bytes_in": 618,
"bytes_out": 533,
"client_ip": "xx",
"client_port": 24039,
"client_proc": "",
"client_server": "",
"direction": "out",
"http": {
"request": {
"headers": {
"content-length": 122,
"content-type": "application/x-www-form-urlencoded"
},
"params": "clientCityName=%E5%8C%97%E4%BA%AC\u0026clientOSName=Win\u0026clientProvinceName=%E5%8C%97%E4%BA%AC\u0026dataType=00\u0026platformStr=01_01_0000_000000_%E9%A6%96%E9%A1%B5\u0026referer="
},
"response": {
"code": 200,
"headers": {
"content-length": 0
},
"phrase": "OK"
}
},
"ip": "101.37.42.237",
"method": "POST",
"path": "/userBehaviorRecord_sendUserBeHaviorData.action",
"port": 80,
"proc": "",
"query": "POST /userBehaviorRecord_sendUserBeHaviorData.action",
"responsetime": 148,
"server": "",
"status": "OK",
"type": "http"
}
3 个回复
medcl - 今晚打老虎。
赞同来自: zhangyufu
配置文件参考:
捕获到的请求:
0c0c0f
赞同来自:
$ ./packetbeat -e -c packetbeat.yml
0c0c0f
赞同来自:
send_headers: ["User-Agent","Cookie","x-real-ip","referer","Set-Cookie","Host","x-forwarded-for"]
ok 结贴