编写Logstash Grok Pattern解析ping日志并提取指定字段
Solution: Grok Pattern for Ping Log Extraction
Got it, let's build a Grok pattern that pulls out all the fields you need from your ping log sample. Here's the full pattern first, then I'll break down each part so you understand what's happening:
%{DAY} %{MONTH} %{MONTHDAY} %{TIME} %{YEAR:timestamp} PING %{DATA} \(%{IPV4:ip_address}\) %{DATA} bytes of data\. %{DATA} bytes from %{DATA} \(%{IPV4}\): icmp_seq=%{NUMBER} ttl=%{NUMBER:ttl:int} time=%{DATA} ms --- %{DATA} ping statistics --- %{NUMBER} packets transmitted, %{NUMBER} received, %{NUMBER}% packet loss, time %{DATA}ms rtt min/avg/max/mdev = %{NUMBER:rtt_min:float}/%{NUMBER:rtt_avg:float}/%{NUMBER:rtt_max:float}/%{NUMBER:rtt_mdev:float} ms
Breakdown of Key Components
Let's go through the parts that matter most for your extraction needs:
- Timestamp:
%{DAY} %{MONTH} %{MONTHDAY} %{TIME} %{YEAR:timestamp}
Captures the full date-time string (Tue Mar 27 06:51:48 2018) into a singletimestampfield. - IP Address:
\(%{IPV4:ip_address}\)
Grabs the IPv4 address inside the parentheses and stores it asip_address(we ignore the second occurrence of the IP since it's identical to the first). - TTL Value:
ttl=%{NUMBER:ttl:int}
Extracts the TTL number (128 in your sample) and casts it as an integer for easier filtering and aggregation later. - RTT Metrics:
rtt min/avg/max/mdev = %{NUMBER:rtt_min:float}/%{NUMBER:rtt_avg:float}/%{NUMBER:rtt_max:float}/%{NUMBER:rtt_mdev:float}
Captures the minimum, average, and maximum RTT values as floats (we include the mdev value too since it's part of the log, but you can remove that segment if you don't need it).
Extracted Fields
When you apply this pattern to your sample log, you'll get these structured fields:
timestamp:Tue Mar 27 06:51:48 2018ip_address:172.217.169.100ttl:128(integer)rtt_min:17.482(float)rtt_avg:17.482(float)rtt_max:17.482(float)
Pro tip: You can test this pattern using the Grok Debugger (either built into Kibana or standalone tools) to tweak it if needed for any variations in your ping logs.
内容的提问来源于stack exchange,提问作者Gakis41
相关产品推荐
相关产品推荐

