elasticsearch Logstash s3:不使用前缀选项为bucket的单个文件夹下的文件编制索引
s3桶:麋鹿 文件夹:系统日志、错误日志等 文件模式:syslog-
elasticsearch Logstash s3:不使用前缀选项为bucket的单个文件夹下的文件编制索引,
elasticsearch,amazon-s3,logstash,prefix,logstash-file,
elasticsearch,Amazon S3,Logstash,Prefix,Logstash File,s3桶:麋鹿 文件夹:系统日志、错误日志等 文件模式:syslog- input { s3 { access_key_id => "" secret_access_key => "" bucket => "elk" region => "eu-central-1" prefix => "syslog/syslog-" additional_settings =>
input {
s3 {
access_key_id => ""
secret_access_key => ""
bucket => "elk"
region => "eu-central-1"
prefix => "syslog/syslog-"
additional_settings => {
force_path_style => true
follow_redirects => false
}
}
}
output {
elasticsearch {
hosts => ["http://localhost:9200"]
index => "syslog-%{+YYYY.MM.dd}"
user => ""
password => ""
}
}
索引发生在bucket中不同文件夹下的所有文件上,只需处理特定文件夹下的文件
我尝试了以下格式的前缀选项,但没有按预期编制索引
系统日志
系统日志/
syslog/syslog-