t
Size: a a a
S
t
D
if [nginx][access][url] != '/' {"Expected one of #, \", ', } что это и как с этим быть?
grok { { match => { "[nginx][access][url]" => ["%{GREEDYDATA:[nginx][access][uri][type]}/%{GREEDYDATA:[nginx][access][uri][query]}"] } } }
}
D
grok{
match => { "message" => ["%{IPORHOST:[nginx][access][remote_ip]} - %{DATA:[nginx][access][user_name]} \[%{HTTPDATE:[nginx][access][time]}\] \"%{WORD:[nginx][access][method]} %{DATA:[nginx][access][url]} HTTP/%{NUMBER:[nginx][access][http_version]}\" %{NUMBER:[nginx][access][response_code]} %{NUMBER:[nginx][access][body_sent][bytes]} \"%{DATA:[nginx][access][referrer]}\" \"%{DATA:[nginx][access][agent]}\""] }
remove_field => "message"
}
}
if [nginx][access][url] != '/' {
grok { { match => { "[nginx][access][url]" => ["%{GREEDYDATA:[nginx][access][uri][type]}/%{GREEDYDATA:[nginx][access][uri][query]}"] } } }
}