filter配置 - elapsed

优质
小牛编辑
139浏览
2023-12-01
  1. filter {
  2. grok {
  3. match => ["message", "%{TIMESTAMP_ISO8601} START id: (?<task_id>.*)"]
  4. add_tag => [ "taskStarted" ]
  5. }
  6. grok {
  7. match => ["message", "%{TIMESTAMP_ISO8601} END id: (?<task_id>.*)"]
  8. add_tag => [ "taskTerminated"]
  9. }
  10. elapsed {
  11. start_tag => "taskStarted"
  12. end_tag => "taskTerminated"
  13. unique_id_field => "task_id"
  14. }
  15. }