喜之助� 2021-12-14 21:23 采纳率: 0%
浏览 65
已结题

logstash使用prune{whielist_names}无数据

想通过logstash中prune{whitelist_names}设置白名单提取相关字段,但是设置后白名单中字段获取不到。
不使用prune的logstash.conf

input {
  beats {
    port => 5044
  }
}
filter {
       json {
        source => "message"
        remove_field => "message"
}
output {
  if [filetype] == "wazuh_alert"{
  elasticsearch {
    hosts => ["127.0.0.1:9200"]
    index => "wazuhalert111-%{+YYYY.MM.dd}"
    #user => "elastic"
    #password => "changeme"
  }

查询得到的数据:

{
  "took" : 4,
  "timed_out" : false,
  "_shards" : {
    "total" : 1,
    "successful" : 1,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 2047,
      "relation" : "eq"
    },
    "max_score" : 1.0,
    "hits" : [
      {
        "_index" : "sdtalerts111-2021.12.14",
        "_type" : "_doc",
        "_id" : "Di3guH0BS36tsJnhov5-",
        "_score" : 1.0,
        "_source" : {
          "input" : {
            "type" : "log"
          },
          "rule" : {
            "level" : 3,
            "description" : "Ossec server started.",
            "id" : "502",
            "firedtimes" : 1,
            "pci_dss" : [
              "10.6.1"
            ],
            "gdpr" : [
              "IV_35.7.d"
            ],
            "tsc" : [
              "CC7.2",
              "CC7.3"
            ],
            "hipaa" : [
              "164.312.b"
            ],
            "nist_800_53" : [
              "AU.6"
            ],
            "groups" : [
              "ossec"
            ],
            "mail" : false,
            "gpg13" : [
              "10.1"
            ]
          },
          "id" : "1639484264.4555795",
          "fileset" : {
            "name" : "alerts"
          },
          "full_log" : "ossec: Ossec started.",
          "location" : "wazuh-monitord",
          "tags" : [
            "beats_input_codec_plain_applied"
          ],
          "host" : {
            "name" : "lbw-ThinkPad"
          },
          "log" : {
            "file" : {
              "path" : "/var/ossec/logs/alerts/alerts.json"
            },
            "offset" : 6903410
          },
          "agent" : {
            "name" : "lbw-ThinkPad",
            "id" : "000"
          },
          "decoder" : {
            "name" : "ossec"
          },
          "filetype" : "sdtalerts666",
          "manager" : {
            "name" : "lbw-ThinkPad"
          },
          "service" : {
            "type" : "wazuh"
          },
          "@timestamp" : "2021-12-14T12:17:45.653Z",
          "ecs" : {
            "version" : "1.11.0"
          },
          "timestamp" : "2021-12-14T20:17:44.530+0800",
          "event" : {
            "dataset" : "wazuh.alerts",
            "module" : "wazuh"
          },
          "@version" : "1"
        }
      },
      {
        "_index" : "sdtalerts111-2021.12.14",
        "_type" : "_doc",
        "_id" : "EC3guH0BS36tsJnhov6A",
        "_score" : 1.0,
        "_source" : {
          "input" : {
            "type" : "log"
          },
          "rule" : {
            "level" : 7,
            "description" : "Host-based anomaly detection event (rootcheck).",
            "id" : "510",
            "firedtimes" : 1,
            "groups" : [
              "ossec",
              "rootcheck"
            ],
            "gdpr" : [
              "IV_35.7.d"
            ],
            "mail" : false
          },
          "id" : "1639484266.4556047",
          "fileset" : {
            "name" : "alerts"
          },
          "full_log" : "File '/usr/local/zeek/spool/tmp/post-terminate-standalone-2021-07-14-19-01-55-25928-crash/.startup' is owned by root and has written permissions to anyone.",
          "location" : "rootcheck",
          "tags" : [
            "beats_input_codec_plain_applied"
          ],
          "host" : {
            "name" : "lbw-ThinkPad"
          },
          "agent" : {
            "name" : "lbw-ThinkPad",
            "id" : "000"
          },
          "log" : {
            "file" : {
              "path" : "/var/ossec/logs/alerts/alerts.json"
            },
            "offset" : 6903891
          },
          "decoder" : {
            "name" : "rootcheck"
          },
          "filetype" : "sdtalerts666",
          "data" : {
            "title" : "File is owned by root and has written permissions to anyone.",
            "file" : "/usr/local/zeek/spool/tmp/post-terminate-standalone-2021-07-14-19-01-55-25928-crash/.startup"
          },
          "manager" : {
            "name" : "lbw-ThinkPad"
          },
          "service" : {
            "type" : "wazuh"
          },
          "@timestamp" : "2021-12-14T12:17:46.653Z",
          "ecs" : {
            "version" : "1.11.0"
          },
          "timestamp" : "2021-12-14T20:17:46.536+0800",
          "event" : {
            "dataset" : "wazuh.alerts",
            "module" : "wazuh"
          },
          "@version" : "1"
        }
      },

kibana显示的字段:

img

使用prune:


input {
  beats {
    port => 5044
  }
}
filter {
       json {
        source => "message"
        remove_field => "message"
       }
       prune {
        whitelist_names => [ "^agent" ]
       }
}
output {
  if [filetype] == "wazuh_alert"{
  elasticsearch {
    hosts => ["127.0.0.1:9200"]
    index => "wazuhalert111-%{+YYYY.MM.dd}"
    #user => "elastic"
    #password => "changeme"
  }

没有数据传送,显示结果没有数据:

img

这应该如何修改呢。

  • 写回答

3条回答 默认 最新

  • 喜之助� 2021-12-14 21:29
    关注

    output 处少写了一个大括号

    评论

报告相同问题?

问题事件

  • 系统已结题 12月22日
  • 创建了问题 12月14日

悬赏问题

  • ¥30 这是哪个作者做的宝宝起名网站
  • ¥60 版本过低apk如何修改可以兼容新的安卓系统
  • ¥25 由IPR导致的DRIVER_POWER_STATE_FAILURE蓝屏
  • ¥50 有数据,怎么建立模型求影响全要素生产率的因素
  • ¥50 有数据,怎么用matlab求全要素生产率
  • ¥15 TI的insta-spin例程
  • ¥15 完成下列问题完成下列问题
  • ¥15 C#算法问题, 不知道怎么处理这个数据的转换
  • ¥15 YoloV5 第三方库的版本对照问题
  • ¥15 请完成下列相关问题!