久久福利_99r_国产日韩在线视频_直接看av的网站_中文欧美日韩_久久一

您的位置:首頁技術文章
文章詳情頁

python實時監控logstash日志代碼

瀏覽:38日期:2022-07-27 10:47:10

實時讀取logstash日志,有異常錯誤keywork即觸發報警。

# /usr/bin/env python3# -*- coding: utf-8 -*-# __author__ = caozhi# create_time 2018-11-12,update_time 2018-11-15# version = 1.0# 錄像高可用報警# 1 讀取日志 使用游標移動# 2 線上業務日志文件會切割,切割后,讀取上一個切割的日志import osimport sysimport jsonimport requestsimport timeimport recini = conf.ini’log_file = logstash.log’def readconf(): try: with open(cini, ’r+’) as f: CONF = json.load(f) except: CONF = {'seek': 0, 'inode': 922817, 'last_file': logstash.log'} writeconf(CONF=CONF) print(’conf.ini 配置文件缺失,自動創建一個新的配置文件’) return CONFdef writeconf(CONF): with open(cini, ’w+’) as e: json.dump(CONF, e)def read_log(log_file, seek): try: f = open(log_file, ’r’) except FileNotFoundError: f = open(logstash.log’, ’r’) seek = 0 print(’上一個文件讀取失敗了,請檢查切割的日志文件’) except: print(’日志文件打開錯誤,退出程序’) sys.exit()f.seek(seek)line = f.readline()new_seek = f.tell()if new_seek == seek: print(’沒有追加日志,退出程序’) sys.exit()while line: try: logstash = json.loads(line) except: CONF = {'seek': 0, 'inode': 922817, 'last_file': '/data/logs/lmrs/logstash.log'} writeconf(CONF=CONF) print(’json數據加載錯誤,重新創建一個新的配置文件’) sys.exit() #if ’’’re.search(time.strftime('%Y:%H:%M', time.localtime()), logstash.get(’log_time’)) and ’’’logstash.get(’rtype’) == 6 and logstash.get(’uri’) == ’/publish’ and logstash.get(’event’) == 0: if logstash.get(’rtype’) == 6 and logstash.get(’uri’) == ’/publish’ and logstash.get(’event’) == 0: value = 1 stream = logstash.get(’name’) print(’{} {}’.format(value, stream)) record(value=value, stream=stream) else: value = 0 stream = 0 line = f.readline()seek = f.tell()f.closereturn value, stream, seekdef record(value, stream): data = [] record = {} record[’metric’] = ’recording_high_availability_monitor’ record[’endpoint’] = os.uname()[1] record[’timestamp’] = int(time.time()) record[’step’] = 60 record[’value’] = value record[’counterType’] = ’GAUGE’ record[’Tags’] = ’{}={}’.format(int(time.time()), stream) data.append(record)if data: print(’這是data的json數據’) print(data) falcon_request = requests.post('http://127.0.0.1:1988/v1/push', data=json.dumps(data)) #falcon_request = requests.post('http://127.0.0.1:1988/v1/push', json=data) print(’json參數請求返回狀態碼為:’ + str(falcon_request.status_code)) print(’json參數請求返回為:’ + str(falcon_request.text))if __name__ == ’__main__’: print() print(’***************************************’) print(’本次執行腳本時間:{}’.format(time.strftime('%Y%m%d_%H%M', time.localtime()))) CONF = readconf() print(’first_CONF :{}’.format(CONF)) print(’NO1.log_file’,log_file) last_inode = CONF[’inode’] inode = os.stat(log_file).st_ino print(’last_inode: {} inode: {}’.format(last_inode, inode))if inode == last_inode: seek = CONF[’seek’] next_file = 0else: log_file = CONF[’last_file’] + time.strftime('-%Y%m%d_', time.localtime()) + str(time.strftime('%H%M', time.localtime()))[:-1] + ’0’ next_file = 1 seek = CONF[’seek’]print(’NO2.log_file’,log_file)value, stream, seek = read_log(log_file=log_file,seek=seek)if next_file: CONF[’seek’] = 0else: CONF[’seek’] = seekCONF[’inode’] = os.stat(logstash.log’).st_inowriteconf(CONF=CONF)print(’last_CONF :{}’.format(CONF))

補充知識:logstash 調用exec

我就廢話不多說了,還是直接看代碼吧!

[elk@Vsftp logstash]$ cat t3.conf input { stdin { } } filter { grok { match => [ 'message','(?m)s*%{TIMESTAMP_ISO8601:time}s*(?<Level>(S+)).*'] } date { match => ['time', 'yyyy-MM-dd HH:mm:ss,SSS'] } mutate { add_field =>['type','tailong'] add_field =>['messager','%{type}-%{message}'] remove_field =>['message'] }} output { if ([Level] == 'ERROR' or [messager] =~ 'Exception' ) and [messager] !~ '溫金服務未連接' and [messager] !~ '調用溫金代理系統接口錯誤' and [messager] !~ 'BusinessException' { exec { command => '/bin/smail.pl '%{messager}' '%{type}' ' } } stdout { codec =>rubydebug } } Vsftp:/root# cat /bin/smail.pl #!/usr/bin/perl use Net::SMTP;use HTTP::Date qw(time2iso str2time time2iso time2isoz); use Data::Dumper;use Getopt::Std;use vars qw($opt_d );getopts(’d:’);# mail_user should be your_mail@163.com $message= '@ARGV'; $env='$opt_d'; sub send_mail{ my $CurrTime = time2iso(time()); my $to_address = shift; my $mail_user = ’zhao.yangjian@163.com’; my $mail_pwd = ’xx’; my $mail_server = ’smtp.163.com’; my $from = 'From: $mail_usern'; my $subject = 'Subject: zjcap infon'; my $info = '$CurrTime--$message'; my $message = <<CONTENT; $infoCONTENT my $smtp = Net::SMTP->new($mail_server); $smtp->auth($mail_user, $mail_pwd) || die 'Auth Error! $!'; $smtp->mail($mail_user); $smtp->to($to_address); $smtp->data(); # begin the data $smtp->datasend($from); # set user $smtp->datasend($subject); # set subject $smtp->datasend('nn'); $smtp->datasend('$messagen'); # set content $smtp->dataend(); $smtp->quit();}; send_mail (’zhao.yangjian@163.com’); 2017-01-12 10:19:19,888 jjjjj Exception{ '@version' => '1', '@timestamp' => '2017-01-12T02:19:19.888Z', 'host' => 'Vsftp', 'time' => '2017-01-12 10:19:19,888', 'Level' => 'jjjjj', 'type' => 'tailong', 'messager' => 'tailong-2017-01-12 10:19:19,888 jjjjj Exception'}

以上這篇python實時監控logstash日志代碼就是小編分享給大家的全部內容了,希望能給大家一個參考,也希望大家多多支持好吧啦網。

標簽: Python 編程
相關文章:
主站蜘蛛池模板: 久久久精品影院 | 国产精品久久久久久久久费观看 | 色免费在线观看 | 欧美在线观看一区 | 一区二区视频 | 国产亚洲精品精品国产亚洲综合 | 国产精品一区二 | 精品视频一区二区三区 | 一区二区三区四区日韩 | 久久青| 精品成人在线 | 欧美极品欧美精品欧美视频 | 中文字幕在线观看一区二区三区 | 狠狠干狠狠操 | 少妇无套高潮一二三区 | 欧美亚洲高清 | 色婷婷综合久久久中文字幕 | 免费的日批视频 | 久久伊人青青草 | 亚洲国内精品 | 亚洲精品电影在线观看 | 国产视频久久久 | 色综合天天综合网国产成人网 | 深夜成人小视频 | 一区二区三区精品 | 天天插天天操天天干 | 日本综合久久 | 日本久久网 | 国产在线h | 欧美黑人一级爽快片淫片高清 | 激情视频网站 | 国产成人精品一区二区三区四区 | 91精品国产高清一区二区三区 | 在线观看日韩精品 | 国产精品视频一二三区 | 在线观看免费国产 | 一区二区三区观看视频 | a视频在线观看 | 日韩欧美在线免费观看 | 国产午夜手机精彩视频 | 日韩一区二区三区在线视频 |