elasticsearch,jdbc,logstash,elastic-stack,Mysql,elasticsearch,Jdbc,Logstash,Elastic Stack" /> elasticsearch,jdbc,logstash,elastic-stack,Mysql,elasticsearch,Jdbc,Logstash,Elastic Stack" />

Mysql logstash配置中的JDBC插件问题

Mysql logstash配置中的JDBC插件问题,mysql,elasticsearch,jdbc,logstash,elastic-stack,Mysql,elasticsearch,Jdbc,Logstash,Elastic Stack,我有这个配置文件(logstash): 用于将数据另存为mySQL数据库。但它不适用于错误消息(列“ip”,“事件”不能为空) 我认为'jdbc.statement'的语法是错误的,我正在尝试修复它。 “output.elasticsearch”工作得很好 { "agent" => { "version" => "7.10.0", "name"

我有这个配置文件(logstash):

用于将数据另存为mySQL数据库。但它不适用于错误消息(列“ip”,“事件”不能为空)

我认为'jdbc.statement'的语法是错误的,我正在尝试修复它。 “output.elasticsearch”工作得很好

{
   "agent" => {
             "version" => "7.10.0",
                "name" => "DESKTOP-GEB1AGR",
                  "id" => "7e109ece-5874-4149-9842-21acb86c9da0",
                "type" => "filebeat",
            "hostname" => "DESKTOP-GEB1AGR",
        "ephemeral_id" => "0730755e-f234-48c4-b7f1-2d2339df0e86"
    },
      "@version" => "1",
    "@timestamp" => 2020-11-23T06:31:59.005Z,
           "log" => {
           "userid" => "192.111.11.111",
        "writetime" => "2020/11/23 15:31:51",
           "target" => "crackme.exe - PID: 5528 - Module: ntdll.dll - Thread: Main Thread 3240 (switched from 19C0)",
            "event" => "dbgRestart"
    },
         "input" => {
        "type" => "log"
    },
           "ecs" => {
        "version" => "1.6.0"
    },
       "message" => "{\"writetime\": \"2020/11/23 15:31:51\", \"userid\": \"111.111.111.111\", \"target\": \"crackme.exe - PID: 5528 - Module: ntdll.dll - Thread: Main Thread 3240 (switched from 19C0)\",  \"event\": \"dbgRestart\"} ",
          "host" => {
                "name" => "DESKTOP-GEB1AGR",
        "architecture" => "x86_64",
                  "os" => {
             "version" => "10.0",
                "name" => "Windows 10 Home",
               "build" => "16299.1087",
              "family" => "windows",
            "platform" => "windows",
              "kernel" => "10.0.16299.1087 (WinBuild.160101.0800)"
        },
                  "id" => "659f1b29-3-2cb22793a39c",
                  "ip" => [
            [0] "fe80::adb9:b",
            [1] "192.168.43.",
            [2] "2001:0:348b:",
            [3] "fe80::180947e"
        ],
            "hostname" => "DESKTOP-GEB1AGR",
                 "mac" => [
            [0] "00:0c:6c:d7",
            [1] "00:00:00:e0"
        ]
    },
          "tags" => [
        [0] "beats_input_codec_plain_applied"
    ]
}
如何使用“writetime”和“event”值? 请给我一些建议

 "log" => {
           "userid" => "192.168.43.129",
        "writetime" => "2020/11/23 15:31:51",
           "target" => "crackme.exe - PID: 5528 - Module: ntdll.dll - Thread: Main Thread 3240 (switched from 19C0)",
            "event" => "dbgRestart"},

如果event是log对象中的一个字段,那么在logstash中,您将其称为“[log][event]”。[log.event]是指名称中有句点的字段。与“[log][userid]”类似

 "log" => {
           "userid" => "192.168.43.129",
        "writetime" => "2020/11/23 15:31:51",
           "target" => "crackme.exe - PID: 5528 - Module: ntdll.dll - Thread: Main Thread 3240 (switched from 19C0)",
            "event" => "dbgRestart"},