zoukankan      html  css  js  c++  java
  • logstash 解析windows iis日志

    logstash-gw.conf  logstash-index.conf
    [elk@Vsftp gw]$ cat logstash-gw.conf 
    input {
            file {
                    type => "gw-app-iis"
                    path => ["/data01/gw/gw-app*"]
                    codec => plain {
                    charset => "ISO-8859-1"
        }
            }
        
    
    
     
    }
    filter {
        grok {
            match => [
                 "message" ,"s*(?<time>([0-9]{4}-[0-9]{2}-[0-9]{2}s+[0-9]{2}:[0-9]{2}:[0-9]{2}))s+%{IPORHOST:clientip}s+%{WORD:verb}s+%{URIPATHPARAM:request}s+-s+(?<port>([0-9]{2}.*?))s+-s+%{IPORHOST:sourceip}s+(?<http_user_agent>(S+s+).*?).*",
                 "message" ,"s*(?<time>([0-9]{4}-[0-9]{2}-[0-9]{2}s+[0-9]{2}:[0-9]{2}:[0-9]{2}))s+%{IPORHOST:clientip}s+%{WORD:verb}s+%{URIPATHPARAM:request}s+(?<src>(S+).*?)s+(?<port>([0-9]{2}.*?))s+-s+%{IPORHOST:sourceip}s+(?<http_user_agent>(S+s+).*?).*",
                 "message","s*(?<time>([0-9]{4}-[0-9]{2}-[0-9]{2}s+[0-9]{2}:[0-9]{2}:[0-9]{2}))s+%{IPORHOST:clientip}s+%{WORD:verb}s+%{URIPATHPARAM:request}.*"
                    ]
           }
    }
    output {
         if [type] == "gw-app-iis" { 
            redis {
                    host => "192.168.11.185"
                    data_type => "list"
                    key => "gw-app-iis:redis"
                    port=>"6379"
                    password => "1234567"
            }
    }
    }

  • 相关阅读:
    pwn1_sctf_2016
    warmup_csaw_2016
    网鼎杯2020 joker逆向
    网鼎杯2020 伪虚拟机wp
    WannaRen病毒逆向分析
    v2ex源代码相关资料
    iOS自学
    ios牛博
    你有什么问题需要问我的吗?
    类族的写法
  • 原文地址:https://www.cnblogs.com/hzcya1995/p/13349869.html
Copyright © 2011-2022 走看看