1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
| /home/app/logstash-2.3.4/bin/logstash -f /home/app/logstash-2.3.4/etc/logstash_indexer.conf
"message" => "0.000 - 10.20.150.91 - - [18/Aug/2016:11:44:10 +0800] test02.corp.test.com \"GET /favicon.ico HTTP/1.1\" 404 727 \"http://test02.corp.test.com/\" \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.75 Safari/537.36\" \"-\" \"-\" - \"10.20.161.126\"",
"@version" => "1",
"@timestamp" => "2016-08-18T03:44:10.705Z",
"path" => "/data/logs/nginx/access.log",
"host" => "test02",
"type" => "nginx access log",
"request_time" => "0.000",
"upstream_time" => "-",
"client_ip" => "10.20.150.91",
"upstream_host" => "-",
"local_time" => "18/Aug/2016:11:44:10 +0800",
"domain" => "test02.corp.test.com",
"verb" => "GET",
"request" => "/favicon.ico",
"http_version" => "1.1",
"upstream_cache_status" => "404",
"bytes" => "727",
"referrer" => "\"http://test02.corp.test.com/\"",
"agent" => "\"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.75 Safari/537.36\"",
"gzip_ratio" => "-",
"x_forword" => "-",
"lvs_vip" => "10.20.161.126"
|