本地localhost:9200环境下Logstash无法输出至Elasticsearch求助
Fixing Logstash-to-Elasticsearch Output for Your Nginx Logs
Let's work through this issue step by step. First, I spot two key problems with your current setup:
- Your
test.confdoesn't include an Elasticsearch output block — that's why your data isn't being sent to your local ES instance atlocalhost:9200. - The existing
datefilter won't function correctly because you haven't first extracted thetimestampfield from your raw Nginx log line.
Revised Logstash Config (test.conf)
Here's an updated configuration that addresses both issues, plus proper parsing for your Nginx access log format:
input { file { path => "C:/logs/nginxAccess.log" start_position => "beginning" # Prevent Logstash from remembering previous read positions (useful for testing) sincedb_path => "NUL" } } filter { # Parse raw Nginx log into structured fields using Grok grok { match => { "message" => '%{IPORHOST:clientip} - - \[%{HTTPDATE:timestamp}\] "%{WORD:method} %{URIPATHPARAM:request} %{DATA:http_version}" %{NUMBER:status} %{NUMBER:bytes_sent} "%{DATA:referrer}" "%{DATA:user_agent}"' } } # Convert extracted timestamp to Elasticsearch's native @timestamp field date { match => [ "timestamp" , "dd/MMM/yyyy:HH:mm:ss Z" ] target => "@timestamp" } } output { # Send data to your local Elasticsearch instance elasticsearch { hosts => ["localhost:9200"] # Define a custom index name (adjust as needed) index => "nginx-access-%{+YYYY.MM.dd}" } # Keep stdout output for debugging stdout { codec => rubydebug } }
Key Explanations:
- Input: Added
sincedb_path => "NUL"to ensure Logstash re-reads the entire log file on each run (great for testing; remove this in production if you want to track read positions). - Filter:
- The
grokpattern matches your Nginx log format and extracts fields likeclientip,request,status, and crucially,timestamp. - The
datefilter converts the human-readabletimestampinto Elasticsearch's standardized@timestampfield, which is required for proper time-based indexing.
- The
- Output: The new
elasticsearchblock sends parsed data to your locallocalhost:9200instance, with a daily rotating index name for easier management.
Testing & Verification:
- Run Logstash with the updated config:
logstash -f test.conf - Check if the index is created in Elasticsearch by running this command in your terminal:
You should see an index named something likecurl localhost:9200/_cat/indices?vnginx-access-2024.05.20(matching the current date). - You can also query the index to confirm data is present:
curl localhost:9200/nginx-access-*/_search?q=*&pretty
内容的提问来源于stack exchange,提问作者Shiva
相关产品推荐
相关产品推荐

