一 logstash配置文件
[root@DNS-Server ~]# cat /etc/logstash/conf.d/java.conf input { file { path => "/var/log/logstash/logstash-plain.log" type => "java-log" codec => multiline { pattern => "^\[(\d{4}-\d{2}-\d{2})" #正则匹配行开始 negate => true what => "previous" #行首结束 } } } output { elasticsearch { hosts => ["192.168.10.10:9200"] index => "javalog-xuan-%{+YYYY.MM}" } }