Ami*_*ram 4 logstash logstash-grok logstash-configuration
我有两个URL(由于安全问题,我将使用虚拟解释)
a> https://xyz.company.com/ui/api/token
b> https://xyz.company.com/request/transaction?date=2016-01-21&token=<tokeninfo>
Run Code Online (Sandbox Code Playgroud)
当您点击'a'中提到的url时,它将生成一个令牌,让它成为一个包含16个字符的字符串
然后该令牌应该用于在令牌参数中进行点'b'的第二次请求
The second url response is important to me i.e is a JSON response, I need
to filter the json data and extract required data and output it to standard
output and elastic search.
Run Code Online (Sandbox Code Playgroud)
有没有办法在logstash中使用插件"http_poller"或任何其他插件.
注意:这些请求URL应该一个接一个地执行,即点"a"url应该首先执行,并且"b"url应该在接收到新令牌后执行.
请建议.
是的,可以混合使用http_poller输入和http输出.
这是我提出的配置:
input {
# 1. trigger new token requests every hour
http_poller {
urls => {
token => "https://xyz.company.com/ui/api/token"
}
interval => 3600
add_field => {"token" => "%{message}"}
}
}
filter {
}
output {
# 2. call the API
http {
http_method => "get"
url => "https://xyz.company.com/request/transaction?date=2016-01-21&token=%{token}"
}
}
Run Code Online (Sandbox Code Playgroud)
UPDATE
如果您希望能够获取API调用的内容并将其存储在ES中,则需要一个混合解决方案.您需要设置一个cron,它将调用运行两个HTTP调用的脚本并将结果存储在一个文件中,然后您可以让logstash拖尾该文件并将结果转发给ES.
shell脚本放在cron上:
#!/bin/sh
# 1. Get the token
TOKEN=$(curl -s -XGET https://xyz.company.com/ui/api/token)
# 2. Call the API with the token and append JSON to file
curl -s -XGET "https://xyz.company.com/request/transaction?date=2016-01-21&token=$TOKEN" >> api_calls.log
Run Code Online (Sandbox Code Playgroud)
上面的脚本可以使用crontab(或类似的)在cron上设置,有很多关于如何实现这一点的例子.
然后logstash配置可以非常简单.它只需要拖尾api_calls.log文件并将文件发送给ES
input {
file {
path => "api_calls.log"
start_position => "beginning"
}
}
filter {
json {
source => "message"
}
}
output {
elasticsearch {
hosts => ["localhost:9200"]
index => "my_index"
document_type" => "my_type"
}
stdout {
codec => "rubydebug"
}
}
Run Code Online (Sandbox Code Playgroud)