zoukankan      html  css  js  c++  java
  • zabbix 插件使用问题

    [elk@dr-mysql01 frontend]$ ../../bin/logstash -f std02.conf 
    Settings: Default pipeline workers: 8
    Pipeline main started
    31`31`
    ArgumentError: comparison of String with 5 failed
                 >= at org/jruby/RubyComparable.java:155
                 >= at org/jruby/RubyString.java:1853
        output_func at (eval):138
       output_batch at /usr/local/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:293
               each at org/jruby/RubyArray.java:1613
             inject at org/jruby/RubyEnumerable.java:852
       output_batch at /usr/local/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:287
        worker_loop at /usr/local/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:232
      start_workers at /usr/local/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:201
    [elk@dr-mysql01 frontend]$ ../../bin/logstash -f std02.conf 
    Settings: Default pipeline workers: 8
    Pipeline main started
    ddsad
    ArgumentError: comparison of String with 5 failed
                 >= at org/jruby/RubyComparable.java:155
                 >= at org/jruby/RubyString.java:1853
        output_func at (eval):138
       output_batch at /usr/local/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:293
               each at org/jruby/RubyArray.java:1613
             inject at org/jruby/RubyEnumerable.java:852
       output_batch at /usr/local/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:287
        worker_loop at /usr/local/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:232
      start_workers at /usr/local/logstash-2.3.4/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.4-java/lib/logstash/pipeline.rb:201
    [elk@dr-mysql01 frontend]$ ^C
    [elk@dr-mysql01 frontend]$ vim std02.conf 
    [elk@dr-mysql01 frontend]$ vim std02.conf 
    [elk@dr-mysql01 frontend]$ cat std02.conf 
    input {
        stdin {
          type => "zj_scan"
        }
     
    }
    filter {
        grok {
                match =>[ 
                 "message","%{IPORHOST:clientip} [%{HTTPDATE:time}] "%{WORD:verb} %{URIPATHPARAM:request}?.* HTTP/%{NUMBER:httpversion}" - %{NUMBER:http_status_code} %{NUMBER:bytes} "(?<http_referer>S+)" "(?<http_user_agent>(S+s+)*S+)" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)", 
                 "message" , "%{IPORHOST:clientip} [%{HTTPDATE:time}] "%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}" - %{NUMBER:http_status_code} %{NUMBER:bytes} "(?<http_referer>S+)" "(?<http_user_agent>(S+s+)*S+)" (%{BASE16FLOAT:request_time}) (%{IPORHOST:http_x_forwarded_for}|-)",
                 "message","%{IPORHOST:clientip} [%{HTTPDATE:time}] "%{WORD:verb} (?<http_url>S+)s+HTTP/%{NUMBER:httpversion}"s+-s+%{NUMBER:http_status_code}s+%{NUMBER:bytes}s+"-"s+"(?<http_user_agent>(S+))"s+(%{BASE16FLOAT:request_time})s+(%{IPORHOST:http_x_forwarded_for}|-)"
                 
            ]
        }  
           geoip {
                            source => "http_x_forwarded_for"
                            target => "geoip"
                            database => "/usr/local/logstash-2.3.4/etc/GeoLiteCity.dat"
                            add_field => [ "[geoip][coordinates]", "%{[geoip][longitude]}" ]
                            add_field => [ "[geoip][coordinates]", "%{[geoip][latitude]}"  ]
                    }
                    mutate {
                            convert => [ "[geoip][coordinates]", "float"]
                            convert => [ "request_time", "float"]
                           add_field =>["response_time","%{request_time}"]
                            convert => [ "response_time", "float"]
                            add_field => [ "[@metadata][zabbix_key]" , "logstash-api-access" ]
                           add_field => [ "[@metadata][zabbix_host]" , "dr-mysql01" ]
                           add_field =>["messager","%{type}%{message}"]
                            remove_field =>["request_time"]
                            remove_field =>["message"]
    
                    }
                  date {
            match => ["time", "dd/MMM/yyyy:HH:mm:ss Z"]
        }
    }
    output {
            	stdout {
    			codec => rubydebug
    		}
    #        if [response_time] >= 5  {
    #          zabbix {
    #                zabbix_host => "[@metadata][zabbix_host]"
    #                zabbix_key => "[@metadata][zabbix_key]"
    #        zabbix_server_host => "192.168.32.55"
    #        zabbix_server_port => "10051"
    #                zabbix_value => "messager"
    #        }
    # }
    }
    [elk@dr-mysql01 frontend]$ ../../bin/logstash -f std02.conf 
    Settings: Default pipeline workers: 8
    Pipeline main started
    121
    {
             "@version" => "1",
           "@timestamp" => "2016-09-27T05:40:46.547Z",
                 "type" => "zj_scan",
                 "host" => "dr-mysql01.zjcap.com",
                 "tags" => [
            [0] "_grokparsefailure"
        ],
        "response_time" => "%{request_time}",
             "messager" => "zj_scan121"
    }
    
    加载zabbix 插件后,只要匹配不上 logstash就会挂掉,不会打印匹配不上的记录

  • 相关阅读:
    2013-10-31 《问题儿童居然一天两更!?》
    2013-10-31 《October 31st, 2013》
    2013-10-31 《三天里什么都没干……总之把目前为止的代码发了吧……》
    日怎么没人告诉我这博客可以改博文界面的显示宽度的
    俗话说打脸哦不打铁要趁热所以记录下替换图片的方法
    GUI好看码难写不是难写是难看我是说码难看不是GUI
    虽然保持了连续代码生产量但是仔细想想也没什么必要
    重写了电话本代码全面更新居然连续三天每天一个程序
    专注写字典三十年问你怕未又被编码卡了简直难以置信
    我就写个字典居然卡了两天重申一遍文字编码日你大爷
  • 原文地址:https://www.cnblogs.com/zhaoyangjian724/p/6199157.html
Copyright © 2011-2022 走看看