Skip to content

alexvaque/solr-grok-logstash

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 

Repository files navigation

Processing Solr Cloud logs using logstash

How to process Solr Logs with Logstash.

Grok expression that extract the collection field.

filter {
    if [type] == "solr-log" {
	grok {
	  match => [ "message", "%{LOGLEVEL:loglevel}  - %{TIMESTAMP_ISO8601:timestamp}; \[c:%{WORD:clustername} s:%{WORD:shardname} r:%{WORD:replicaname} x:%{WORD:collectionname}\] %{NOTSPACE:javamethod}; slow: \[%{WORD:collectionname2}\] webapp=/%{WORD:webapp} path=/%{WORD:path} params=%{DATA:rawrequest} hits=%{INT:hits} status=%{INT:status} QTime=%{INT:qtime}" ]
	  overwrite => [ "message" ]
	}
	mutate {
	  remove => [ "rawrequest" ]  # Removes the 'client' field
	}
    }
}

Please, If you have improvements in that Grok parse, let me know please. Feel you free to update this repository.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published