返回介绍

codec配置 - netflow

发布于 2020-06-28 10:03:41 字数 6891 浏览 1499 评论 0 收藏 0

  1. input {
  2. udp {
  3. port => 9995
  4. codec => netflow {
  5. definitions => "/home/administrator/logstash-1.4.2/lib/logstash/codecs/netflow/netflow.yaml"
  6. versions => [5]
  7. }
  8. }
  9. }
  10. output {
  11. stdout { codec => rubydebug }
  12. if ( [host] =~ "10.1.1[12].1" ) {
  13. elasticsearch {
  14. index => "logstash_netflow5-%{+YYYY.MM.dd}"
  15. host => "localhost"
  16. }
  17. } else {
  18. elasticsearch {
  19. index => "logstash-%{+YYYY.MM.dd}"
  20. host => "localhost"
  21. }
  22. }
  23. }
  1. curl -XPUT localhost:9200/_template/logstash_netflow5 -d '{
  2. "template" : "logstash_netflow5-*",
  3. "settings": {
  4. "index.refresh_interval": "5s"
  5. },
  6. "mappings" : {
  7. "_default_" : {
  8. "_all" : {"enabled" : false},
  9. "properties" : {
  10. "@version": { "index": "analyzed", "type": "integer" },
  11. "@timestamp": { "index": "analyzed", "type": "date" },
  12. "netflow": {
  13. "dynamic": true,
  14. "type": "object",
  15. "properties": {
  16. "version": { "index": "analyzed", "type": "integer" },
  17. "flow_seq_num": { "index": "not_analyzed", "type": "long" },
  18. "engine_type": { "index": "not_analyzed", "type": "integer" },
  19. "engine_id": { "index": "not_analyzed", "type": "integer" },
  20. "sampling_algorithm": { "index": "not_analyzed", "type": "integer" },
  21. "sampling_interval": { "index": "not_analyzed", "type": "integer" },
  22. "flow_records": { "index": "not_analyzed", "type": "integer" },
  23. "ipv4_src_addr": { "index": "analyzed", "type": "ip" },
  24. "ipv4_dst_addr": { "index": "analyzed", "type": "ip" },
  25. "ipv4_next_hop": { "index": "analyzed", "type": "ip" },
  26. "input_snmp": { "index": "not_analyzed", "type": "long" },
  27. "output_snmp": { "index": "not_analyzed", "type": "long" },
  28. "in_pkts": { "index": "analyzed", "type": "long" },
  29. "in_bytes": { "index": "analyzed", "type": "long" },
  30. "first_switched": { "index": "not_analyzed", "type": "date" },
  31. "last_switched": { "index": "not_analyzed", "type": "date" },
  32. "l4_src_port": { "index": "analyzed", "type": "long" },
  33. "l4_dst_port": { "index": "analyzed", "type": "long" },
  34. "tcp_flags": { "index": "analyzed", "type": "integer" },
  35. "protocol": { "index": "analyzed", "type": "integer" },
  36. "src_tos": { "index": "analyzed", "type": "integer" },
  37. "src_as": { "index": "analyzed", "type": "integer" },
  38. "dst_as": { "index": "analyzed", "type": "integer" },
  39. "src_mask": { "index": "analyzed", "type": "integer" },
  40. "dst_mask": { "index": "analyzed", "type": "integer" }
  41. }
  42. }
  43. }
  44. }
  45. }
  46. }'

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。
列表为空,暂无数据
    我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
    原文