这个是我用的配置,如下:
<match td.*.*>@type tdlogapikey YOUR_API_KEYauto_create_tablebuffer_type filebuffer_path /var/log/td-agent/buffer/td<secondary>@type filepath /var/log/td-agent/failed_records</secondary></match><match debug.**>@type stdout</match><source>@type forward</source><source>@type httpport 8888</source><source>@type debug_agentbind 127.0.0.1port 24230</source><source>@type tailpath /var/log/nginx/moat.access.logpos_file /var/log/td-agent/moat-nginx-access.log.postag moat.nginx.accessformat /^(?<remote>[^ ]*) (?<host>[^ ]*) (?<user>[^ ]*) \[(?<time>[^\]]*)\] "(?<method>\S+)(?: +(?<path>[^\"]*) +\S*)?" (?<code>[^ ]*) (?<size>[^ ]*)(?: "(?<referer>[^\"]*)" "(?<agent>[^\"]*)" "(?<forwarded>[^\"]*)") (?<request_id>[^ ]*) (?<request_time>[^ ]*)$/time_format %d/%b/%Y:%H:%M:%S %z</source><source>@type tailpath /var/log/nginx/moat.error.logpos_file /var/log/td-agent/moat-nginx-error.log.postag moat.nginx.errorformat /^(?<time>[^ ]+ [^ ]+) \[(?<log_level>.*)\] (?<pid>\d*).(?<tid>[^:]*): (?<message>.*)$/time_format %Y/%m/%d %H:%M:%S</source><filter moat.nginx.*>@type record_transformer<record>hostname ${hostname}area usa</record></filter><match moat.nginx.*>@type elasticsearchlogstash_format truehost 172.31.4.58port 9200logstash_prefix shaohualee-nginx-qatype_name fluentdcontent_type application/jsontemplate_name shaohualee-nginxtemplate_file /etc/td-agent/shaohualee-nginx.jsontemplate_overwrite true</match><source>@type tailpath /opt/app/security-moat-sqa/logs/moat.logpos_file /var/log/td-agent/moat-api-access.log.postag moat.api.access<parse>@type multi_format<pattern>format /^(?<level>[^ ]*) \[(?<time>[^\]]*)\] "(?<service>[\S\s]+)" -- "(?<path>[\S\s]+)" "(?<app_version>[\S\s]+)" "(?<phone_model>[\S\s]+)" (?<token>\S+) (?<open_udid>\S+) (?<country>\S+) (?<language>\S+) (?<request_id>\S+) (?<user_id>\S+) (?<station_sn>\S+) (?<device_sn>\S+) (?<latency>[^ ]*) (?<code>[^ ]*) "(?<message>[\S\s]+)" (?<params>[\s\S]*)$/time_key time</pattern><pattern>format /^(?<level>[^ ]*) \[(?<time>[^\]]*)\] "(?<service>[\S\s]+)" ~~ "(?<tag>[\S\s]+)" (?<action_id>\S+) (?<action_sub_id>\S+) (?<latency>[^ ]*) "(?<message>[\S\s]+)" (?<params>[\s\S]*)$/time_key time</pattern></parse>time_format %Y-%m-%dT%H:%M:%S%z</source><source>@type tailpath /opt/app/security-moat-dev/logs/moat.logpos_file /var/log/td-agent/boat-api-access.log.postag moat.api.access<parse>@type multi_format<pattern>format /^(?<level>[^ ]*) \[(?<time>[^\]]*)\] "(?<service>[\S\s]+)" -- "(?<path>[\S\s]+)" "(?<app_version>[\S\s]+)" "(?<phone_model>[\S\s]+)" (?<token>\S+) (?<open_udid>\S+) (?<country>\S+) (?<language>\S+) (?<request_id>\S+) (?<user_id>\S+) (?<station_sn>\S+) (?<device_sn>\S+) (?<latency>[^ ]*) (?<code>[^ ]*) "(?<message>[\S\s]+)" (?<params>[\s\S]*)$/time_key time</pattern><pattern>format /^(?<level>[^ ]*) \[(?<time>[^\]]*)\] "(?<service>[\S\s]+)" ~~ "(?<tag>[\S\s]+)" (?<action_id>\S+) (?<action_sub_id>\S+) (?<latency>[^ ]*) "(?<message>[\S\s]+)" (?<params>[\s\S]*)$/time_key time</pattern></parse>time_format %Y-%m-%dT%H:%M:%S%z</source><filter moat.api.*>@type record_transformer<record>hostname ${hostname}area usa</record></filter><match moat.api.*>@type elasticsearchlogstash_format truehost 172.31.4.58port 9200logstash_prefix shaohualee-api-sqatype_name fluentdcontent_type application/jsontemplate_name shaohualee-apitemplate_file /etc/td-agent/shaohualee-api.jsontemplate_overwrite true</match><source>@type tailpath /opt/app/security-moat-sqa/logs/logging.logpos_file /var/log/td-agent/moat-logging-report.postag logging.report.moat<parse>@type json</parse></source><source>@type tailpath /opt/app/security-emqtt-sqa/logs/logging.logpos_file /var/log/td-agent/boat-logging-report.postag logging.report.boat<parse>@type json</parse></source><match logging.report.*>@type elasticsearchlogstash_format truehost 172.31.4.58port 9200logstash_prefix logging-short-qatype_name doccontent_type application/json</match><system>log_level error</system>#@include conf.d/*.conf
可以这样子在centos7上启动td-agent
sudo systemctl start td-agent.servicesudo systemctl status td-agent.service #这个很有用,可以查看日志在哪
搜索
标签
study
ab
amap
apache
apahe
awk
aws
bat
centos
CFS
chrome
cmd
cnpm
composer
consul
crontab
css
curl
cygwin
devops
di
docker
docker,docker-compose
ethereum
excel
fiddler
fluentd
framework
front-end
git
gitgui
github
glide
go
golang
gorm
grafana
gzip
ioc
item2
iterm2
javascript
jenkins
jsonp
kafka
laradock
laravel
larval
linux
liunux
log
mac
mac, wi-fi
macos
magento
mariaDB
minikube
mongoDB
msp
mysql
netbeans
nginx
nodejs
nohup
npm
nsq
php
php-fpm
php7
phpstorm
php扩展
Protobuf
python
redis
scp
server
shell
soap
socket
socket5
sql
sre
ssdb
ssh
ssl
study
sublime
swift
system
td-agent
uml
v2ray
vagrant
vagrnat
vim
vpn
vue
vue.js
webpack
webrtc
websocket
webtatic
windows
windows7
word
wps
xdebug
yarn
yii2
yum
zookeeper
世界国家
互联网
以太坊
分类
前端
小程序
打印机
排序算法
搞笑
权限
粤语
缓存
网络
虚拟机
视频
设计模式
项目管理
热门文章
友情链接