add docker tokenizer to extract http header from nginx
This commit is contained in:
parent
133e2fd382
commit
c2063ef4d7
@ -21,7 +21,8 @@ processors:
|
|||||||
host: "unix:///var/run/docker.sock"
|
host: "unix:///var/run/docker.sock"
|
||||||
- add_host_metadata: ~
|
- add_host_metadata: ~
|
||||||
- dissect:
|
- dissect:
|
||||||
tokenizer: '%{nginx.remote_addr} - %{nginx.remote_user} [%{nginx.time}] %{nginx.host} "%{nginx.request}" %{nginx.status|integer} %{nginx.http_referer} "%{nginx.http_user_agent}" %{nginx.http_x_forwarded_for} %{nginx.request_id} "%{nginx.geoip_country_name}" %{nginx.geoip_country_code} %{nginx.geoip.lat|double} %{nginx.geoip.lon|double}'
|
tokenizer: '%{nginx.remote_addr} - %{nginx.remote_user} [%{nginx.time}] %{nginx.host} "%{nginx.request}" %{nginx.status|integer} %{nginx.http_referer} "%{nginx.http_user_agent}" %{nginx.http_x_forwarded_for} %{nginx.request_id} "%{nginx.geoip_country_name}" %{nginx.geoip_country_code} %{nginx.geoip.lat|double} %{nginx.geoip.lon|double} req_header:"%{nginx.header.req}" resp_header:"%{nginx.header.resp}"'
|
||||||
|
trim_values: all
|
||||||
target_prefix: ""
|
target_prefix: ""
|
||||||
field: "message"
|
field: "message"
|
||||||
when:
|
when:
|
||||||
|
Loading…
x
Reference in New Issue
Block a user