From 592da85a8120d73ab42019b8b2f96acf3afa305c Mon Sep 17 00:00:00 2001 From: Alex Robinson Date: Thu, 7 Jan 2016 20:41:22 -0500 Subject: [PATCH 1/2] Parse system logs into structured messages in fluentd. This allows you to filter based on components of the log, like their severity, in the developers console or elasticsearch. --- .../fluentd-es-image/td-agent.conf | 39 +++++++++++++++---- .../fluentd-gcp-image/google-fluentd.conf | 39 +++++++++++++++---- 2 files changed, 64 insertions(+), 14 deletions(-) diff --git a/cluster/addons/fluentd-elasticsearch/fluentd-es-image/td-agent.conf b/cluster/addons/fluentd-elasticsearch/fluentd-es-image/td-agent.conf index bbe39854181..1e2013da01d 100644 --- a/cluster/addons/fluentd-elasticsearch/fluentd-es-image/td-agent.conf +++ b/cluster/addons/fluentd-elasticsearch/fluentd-es-image/td-agent.conf @@ -115,65 +115,90 @@ read_from_head true +# Example: +# 2015-12-21 23:17:22,066 [salt.state ][INFO ] Completed state [net.ipv4.ip_forward] at time 23:17:22.066081 type tail - format none + format /^(?