0
点赞
收藏
分享

微信扫一扫

logstash mutate gsub 正则替换内容

英乐 2023-02-13 阅读 31

记录下,网络设备默认有些日志内容无用,用正则替换删除

input{

       udp {host => "127.0.0.1" port => 515 type => "Hillstone"}

}

filter {

   mutate {

                gsub => [ "message", "\, vr trust-vr, user -@UNKNOWN, host -, rule [12456789]0\n\u0000", "" ]

       remove_field => [ "@version" ]

  }

}

message :日志字段

, vr trust-vr, user -@UNKNOWN, host -, rule [12456789]0\n\u0000  :日志内容

@version:默认字段

举报

相关推荐

0 条评论