# /etc/rsyslog.d/docker.rb
version=2
# My sample record
# [Apr 25 12:00]$CONTAINER_HOSTNAME:INFO:Package.Module.Sub-Module:Hello World
#
# Here there is the rule to parse the log records into trees
rule=:[%date:char-to:]%]%hostname:char-to::%:%level:char-to::%:%file:char-to::%:%message:rest%
#
# alternative to set date field in rfc3339 format
# rule=:[%date:date-rfc3339%]%hostname:char-to::%:%level:char-to::%:%file:char-to::%:%message:rest%
^{pr2}$
下一步安装kibana可以“配置索引模式”,只需将“index name or pattern”设置为“docker logs”,将“Time field name”设置为“@timestamp”
我是如何解决这个问题的:
^{pr2}$
下一步安装kibana可以“配置索引模式”,只需将“index name or pattern”设置为“docker logs”,将“Time field name”设置为“@timestamp”
注意,没有对日志源(172.17.0.0/16)的控制;发送到$HOST:$PORT的每个日志记录如果正确解析,都将插入到elasticsearch索引中。在
相关问题 更多 >
编程相关推荐