logstash/etc/agent.conf.example
2011-02-27 02:17:38 -08:00

29 lines
390 B
Text

input {
file {
path => [ "/var/log/messages", "/var/log/*.log" ]
type => "linux-syslog"
}
}
filter {
grok {
type => "linux-syslog"
pattern => "%{SYSLOGLINE}"
}
date {
type => "linux-syslog"
timestamp => "MMM dd HH:mm:ss"
timestamp8601 => ISO8601
}
}
output {
stdout {
}
elasticsearch {
index => "logstash"
type => "%{@type}"
}
}