Tag: elasticsearch logstash

如何在logstash配置文件中添加ruby代码?

我尝试使用logstash将日志发送到Windows事件。 添加了一些ruby代码之后;它在error下面创建。如何将日志发送到windoes事件? input { file { type => “json” path => [“C:/Temp/logs/*.json”] start_position => “beginning” codec => “json” discover_interval => 120 stat_interval => 60 sincedb_write_interval => 60 close_older => 60 } } filter { mutate { remove_field => [ “path” ] } ruby { code => ” require ‘win32/eventlog’ logger = Win32::EventLog.new logger.report_event(:event_type => Win32::EventLog::INFO, […]