:
input {
beats { port => 5044 }
}
filter {
if [type] == "myType" or [type] == 'myType2' {
codec => multiline {
pattern => "^<%{INT}>%{INT}\s|%{TIMESTAMP_ISO8601}"
what => "previous"
negate=> true
}
grok {
patterns_dir => ["/etc/logstash/patterns"]
match => { "message" => ["%{MYLOG}", "%{MYLOG_V2}"] }
overwrite => ['message']
}
date {
match => [ "timestamp" ,"ISO8601", "HH:mm:ss,SSS MM dd yyyy" ]
locale => "en"
}
mutate {
remove_field => ["timestamp", "hostname"]
}
}
}
output {
elasticsearch {
hosts => ["http://localhost:9200"] index => "%{[@metadats][beat]-%{+YYYY.MM.dd}}"
}
вылетает с ошибкой
[2020-08-09T08:05:13,134][INFO ][logstash.runner] Starting Logstash {"logstash.version"=>"7.7.0"}
[2020-08-09T08:05:17,168][ERROR][logstash.agent] Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of [ \\t\\r\\n], \"#\", \"{\" at line 3, column 15 (byte 70) after input {\n if [type] == \"myType\" or [type] == 'myType2' {\t\t\n codec ", :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:58:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:66:in `compile_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:28:in `block in compile_sources'", "org/jruby/RubyArray.java:2577:in `map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:27:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:181:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:67:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:43:in `initialize'", "/usr/share/logstash/logstascore/lib/logstash/pipeline_action/create.rb:52:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:342:in `block in converge_state'"]}
[2020-08-09T08:05:17,756][INFO ][logstash.agent] Successfully started Logstash API endpoint {:port=>9600}
[2020-08-09T08:05:22,720][INFO ][logstash.runner] Logstash shut down.
что не так с конфигурацией ?
В логе написано
Обсуждают сегодня