logstash配置

input {
    tcp {
        port => 514
        type => syslog
    }
    udp {
        port => 514
        type => syslog
    }
}
output {
    kafka {
        bootstrap_servers => "localhost:9092"
        topic_id => "mysql_log"
    }

}

input {
    kafka{
        bootstrap_servers => "localhost:9092"
        group_id => "logstash"
        topics => ["mysql_audit"]
        codec => "json"
    }
}
output {
    elasticsearch{
        hosts => "localhost"
        index => "db_alert-%{+YYYY.MM.dd}"
        user => ""
        password => ""

    }

}

原文地址:https://www.cnblogs.com/hanfeihan1992/p/8336066.html