记录下,网络设备默认有些日志内容无用,用正则替换删除
input{
udp {host => "127.0.0.1" port => 515 type => "Hillstone"}
}
filter {
mutate {
gsub => [ "message", "\, vr trust-vr, user -@UNKNOWN, host -, rule [12456789]0\n\u0000", "" ]
remove_field => [ "@version" ]
}
}
message :日志字段
, vr trust-vr, user -@UNKNOWN, host -, rule [12456789]0\n\u0000 :日志内容
@version:默认字段
标签:mutate,message,host,vr,gsub,12456789,日志,logstash From: https://blog.51cto.com/luyafei/6054482