编写logstash-to-es.conf文件
input {
tcp {
host => "127.0.0.1"
port => 4560
codec => json {
charset => "UTF-8"
}
}
}
filter {
json {
source => "message"
}
}
output {
elasticsearch {
hosts => ["localhost:9200"]
manage_template => false
index => "logstash-%{+YYYY.MM.dd}"
document_type => "logstash"
}
}
将logstash-to-es.conf 放入 logstash的bin目录下
启动logstash ...logstash-6.8.10logstash-6.8.10bin> .logstash -f logstash-to-es.conf
启动elasticSearch
启动项目日志就会从logstash写入elasticsearch



