The correction is integrated into the TP (See the green boxes)
What you will learn in this TP
- Install Logstash
- Build a pipeline
- use the file input
- Combine different filters
- use the file output
- use conditions
- use variables
Introduction #
What you will learn in this section
- Install Logstash
- Build a pipeline
- use the file input
- Combine different filters
- use the file output
- use conditions
- use variables
This lab aims to teach you how to build a simple pipeline that will read a log file, process it and write its output to a new file
Prerequisites #
You must have a Linux machine with Logstash installed. If you do not have a machine or test environment, we invite you to do the lab on installing Logstash. For those doing the lab on the test environment, you can ask Vagrant to install Logstash:export DEPLOY_LOGSTASH=true; vagrant upInputs configuration #
You must create a file in /etc/logstash/conf.d named "0-input-file-nginx-access.conf".WARNING: In this lab, we specified the configuration file name (0-input-file-nginx-access.conf) but in a company, you will have to build your own naming standard that fits your context.
Reading a file
In this file, you must add the logstash configuration to read the contents of the file "/var/log/rousseltm/nginx-access.log". If you use our Vagrant test environment, the log files will already be present on the VM in the /var/log/rousseltm folder. Otherwise, you will have to copy them manually:
Filters configuration #
You must create a second file named "100-filter-nginx-access.conf".
Data extraction
You must identify the most suitable filter for a flat file and put the configuration that will extract the fields from the previously read log file knowing that this file has a single log format
We choose dissect because it is the fastest plugin to read flat files and also because there is only one log format. After analysis we get this mapping for our dissect configuration:
As indicated during the course, do ECS as soon as possible.%{client.ip} - - [%{nginx.access.time}] "%{http.request.method} %{url.original} HTTP/%{http.version}" %{http.response.status_code} %{http.response.body.bytes} "%{http.request.referrer}" "%{user_agent.original}"Type modification
We want to convert the "http_code" field to an integer. Indeed, there are often arithmetic operations on this field when making restitutions (dashboard, alerts...). For example, display all codes between 200 and 205.
We will therefore use 'convert_datatype' to do it:
convert_datatype => { http_code => "int" }Date adaptation
As you noticed in the provided log file, the logs are not sorted. If you do not adapt the '@timestamp' field, you will have logs sorted by appearance in the file instead of sorting by generation date of the log line.
We will therefore use 'date' to do it:
date { match => [ "nginx.access.time", "dd/MMM/yyyy:HH:mm:ss Z" ] target => "@timestamp" }Field deletion
We want to remove the fields- event.original
- message: as we have already extracted the information that interests us
WARNING: This is a good practice to save storage space and performance.
In other labs, we will see that 'message' should only be removed in cases where we have no filter errors.We add a remove_field block and this gives us globally:
Outputs configuration #
You must create a file in /etc/logstash/conf.d named "200-output-file-nginx-access.conf".
Writing to a file
In this file, you must add the logstash configuration so that it writes our processed log to the file "/var/log/rousseltm/parsed/TYPE.json"
This configuration will allow you to write to the file:
Difficulty level : ●●○○○ (2/5)
Course Glossary
Logstash
An open-source, server-side data processing pipeline that ingests data from a multitude of sources simultaneously, transforms it, and then sends it to...
Recommended Articles
License consumption types
Understand the evolution of billing in Dynatrace: the difference between the old licensing model ...
Grafana Alloy: The importance of Self-Monitoring
Discover why and how to configure Grafana Alloy so that it monitors itself, collecting its own lo...
Grafana Alloy: Understanding and exploiting the User Interface (UI)
Discover how to enable, secure, and use Grafana Alloy's built-in web interface to visualize your ...
Grafana Alloy: Introduction and Architecture
Discover the fundamental concepts of Grafana Alloy, the transition from the static Agent to Alloy...
Grafana Alloy: Syntax and Configuration (Alloy Language: River)
As part of a Grafana training or observability training, master the declarative syntax of Grafana...
Grafana Alloy: Metrics Collection (Prometheus & Ecosystem)
Learn how to configure Grafana Alloy to collect, transform, and forward metrics using the Prometh...
Grafana Alloy: Log Management with Loki
Discover how to configure Grafana Alloy to read log files, journald, or network streams, process ...
Grafana Alloy: Trace Management with Tempo
Dive into distributed trace processing. Learn how to ingest OTLP, Jaeger, or Zipkin traces with G...
Grafana Alloy: Continuous Profiling with Pyroscope
Discover how to configure continuous profiling in your environments using Grafana Alloy and Pyros...
Grafana Alloy: Advanced Deployment and Clustering
Learn how to manage large-scale Grafana Alloy deployments. Configure Clustering mode for high ava...
Grafana Assistant: AI at the service of observability
Discover Grafana Assistant, the artificial intelligence integrated into Grafana Cloud. Learn how ...
Grafana Alloy vs OpenTelemetry Collector: Which One Should You Choose?
A detailed comparison between Grafana Alloy and the OpenTelemetry Collector. Discover the strengt...
Grafana Alloy vs Dynatrace ActiveGate: Which to choose?
Comparison between Grafana Alloy and Dynatrace ActiveGate. Understand the fundamental differences...