tupaiopiao 2022-11-03 17:26 采纳率: 80.3%
浏览 3
已结题

logstash用grok进行日志过滤截取

logstash接收到的日志内容"message" => "{"@timestamp":"2022-11-03T16:23:21.084+08:00","@version":"1","message":"==> Preparing: SELECT COUNT(handle_code) \"triggerDayCount\", SUM(CASE WHEN (trigger_code in (0, 200) and handle_code = 0) then 1 else 0 end) as \"triggerDayCountRunning\", SUM(CASE WHEN handle_code = 200 then 1 else 0 end) as \"triggerDayCountSuc\" FROM xxl_job_log WHERE trigger_time BETWEEN ? and ?","logger_name":"com.xxl.job.admin.dao.XxlJobLogDao.findLogReport","thread_name":"xxl-job, admin JobLogReportHelper","level":"DEBUG","level_value":10000,"tags":["MYBATIS"],"appname":"xxlAdmin"}"
这个用grok怎么按字段截取,
比如"level_value":10000, 截取成leve_value:10000这种

  • 写回答

0条回答 默认 最新

    报告相同问题?

    问题事件

    • 系统已结题 11月11日
    • 创建了问题 11月3日