我的目标是,读到3号地基底和上载的茨夫档案中的数据,但是,在Csv文档中,arrow(=>)正用 j子数据输入(以下)上校。
记录仪表
input {
kinesis {
application_name => "logstash"
kinesis_stream_name => "events"
type => "kinesis"
region => "us-east-1"
profile => "default"
metrics => "cloudwatch"
codec => "json"
}
}
filter {
grok {
match => { "[data][ti]" => "%{YEAR:event_year}-%{MONTHNUM2:event_month}-%{MONTHDAY:event_day}" }
}
}
output {
s3 {
bucket => "test-logstash"
region => "us-east-1"
prefix => "%{event_year}/%{event_month}/%{event_day}/%{[data][brandid]}/%{[data][event_name]}"
encoding => "none"
codec => csv {
separator => "␁"
}
size_file => 200000000
time_file => 60
}
}