System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) · Lección

Filtros y pipelines de Logstash

Explore la configuración avanzada de Logstash, incluida la lógica condicional, varios pipelines y filtros personalizados para transformaciones de datos complejas.

Lección 2 de 411 pasos

Filtros y pipelines de Logstash es una lección gratuita de System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) en CoddyKit. Esta es la lección 2 de 4. Puedes leer la lección completa abajo gratuitamente — luego la practicas en el navegador con un editor de código integrado y un tutor de IA 24/7. Forma parte de la ruta de aprendizaje de System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry), y tu progreso se sincroniza en la web y la app de CoddyKit. El curso de System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) incluye 4 lecciones en total.

Partes de esta lección aún no han sido traducidas y se muestran en inglés.

Intro to Advanced Logstash

Welcome to an advanced look at Logstash! So far, you've learned how to get logs into Logstash and apply basic filters. But what happens when your data gets more complex?

In this lesson, we'll explore powerful techniques like conditional logic, managing multiple pipelines, and leveraging advanced filters for intricate data transformations. This will help you handle real-world logging challenges.

Conditional Logic: The 'if' Statement

Not all logs are created equal! You might have different log formats coming from various services, or you might want to process events differently based on their content.

Conditional logic allows Logstash to apply filters or outputs only when certain conditions are met. This is achieved using if statements, similar to programming languages.

  • Use if to check field values, tags, or other event properties.
  • Apply specific filters or actions only to matching events.

Conditional Logic in Action

Let's see a simple example. We'll use if to check if a field named type exists and has a specific value. If it does, we'll add a tag.

Try inputting {"message": "Hello", "type": "app_log"} and then {"message": "World"} to see the difference.

input {
  stdin {
    codec => json
  }
}
filter {
  if [type] == "app_log" {
    mutate {
      add_tag => ["processed_app_log"]
    }
  }
}
output {
  stdout {
    codec => rubydebug
  }
}

Beyond 'if': Else and Else If

Just like in programming, you can extend your conditional logic with else if and else blocks. This allows for more complex branching and ensures every event is handled appropriately.

Logstash executes these conditions sequentially. The first matching condition's block is executed, and then it moves on.

  • if [field] == "value": Executes if the condition is true.
  • else if [another_field] == "another_value": Executes if the first if was false, and this condition is true.
  • else: Executes if none of the preceding if or else if conditions were true.

Multiple Pipelines: Why Separate?

As your system grows, you might be collecting logs from many different sources (e.g., web servers, databases, security devices). Each source might require entirely different processing logic.

Multiple pipelines allow you to isolate and manage these distinct processing flows independently. Instead of one giant, complex Logstash configuration, you can have several smaller, focused ones.

  • Isolation: Errors in one pipeline won't affect others.
  • Resource Management: Assign specific resources to different pipelines.
  • Modularity: Easier to develop, test, and maintain configurations.

Configuring Multiple Pipelines

To use multiple pipelines, you define them in a file called pipelines.yml, usually located in your Logstash configuration directory (e.g., /etc/logstash/pipelines.yml).

Each entry specifies a unique ID, the path to its configuration file (.conf), and optional settings like number of worker threads.

Example pipelines.yml:

- pipeline.id: web_logs
path.config: "/etc/logstash/conf.d/web-pipeline.conf"
- pipeline.id: db_logs
path.config: "/etc/logstash/conf.d/db-pipeline.conf"

Deep Dive: The Ruby Filter

Sometimes, built-in Logstash filters aren't enough for very specific or complex data transformations. That's where the ruby filter comes in!

The ruby filter allows you to execute arbitrary Ruby code within your Logstash pipeline. This provides immense flexibility to manipulate events in ways not possible with standard filters.

  • Use for: Complex string manipulations, mathematical operations, custom data lookups, or logic that depends on multiple fields.
  • Caution: Can impact performance if not used carefully.

Ruby Filter Example

Let's use the ruby filter to create a new field that combines parts of existing fields and calculates a value.

Try inputting: {"user_id": "123", "item_count": 5, "price_per_item": 10.5}

input {
  stdin {
    codec => json
  }
}
filter {
  ruby {
    code => "
      event.set('total_cost', event.get('item_count').to_f * event.get('price_per_item').to_f)
      event.set('user_item_summary', 'User ' + event.get('user_id') + ' bought ' + event.get('item_count').to_s + ' items.')
    "
  }
}
output {
  stdout {
    codec => rubydebug
  }
}

Advanced Mutate Operations

The mutate filter is a workhorse for basic field manipulation, but it has some advanced operations that are incredibly useful:

  • split: Splits a string field into an array based on a delimiter.
  • join: Joins an array field into a string using a specified separator.
  • convert: Changes the data type of a field (e.g., string to integer, float to string).
  • rename: Changes the name of an existing field.

These operations help you shape your data precisely for storage and analysis.

Quiz: Logstash Logic

Which of the following are valid reasons to use multiple Logstash pipelines?

Recap: Advanced Logstash Config

Great job! You've leveled up your Logstash skills. We covered:

  • How conditional logic (if, else if, else) allows for dynamic event processing.
  • The benefits and configuration of multiple pipelines for modular and isolated data flows.
  • Leveraging the powerful ruby filter for highly custom data transformations.
  • Advanced operations within the mutate filter like split, join, and convert.

These techniques are crucial for building robust and adaptable Logstash configurations for complex, real-world data.

Gratis para empezar

Aprende System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) con un tutor de IA — gratis

Escribe y ejecuta código real en tu navegador, obtén ayuda instantánea de un tutor de IA disponible 24/7 y continúa donde lo dejaste en la web o en la aplicación.

Cursos
12
Lecciones
48

Preguntas frecuentes

¿La lección «Filtros y pipelines de Logstash» es gratis?

Sí — el texto completo de «Filtros y pipelines de Logstash» es gratis para leer aquí en la web. Para practicarla de forma interactiva (editor de código integrado y tutor de IA 24/7) y desbloquear el resto del curso de System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry), actualiza a CoddyKit PRO. El curso de System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) incluye 4 lecciones en total.

¿Qué aprenderé en «Filtros y pipelines de Logstash»?

Explore la configuración avanzada de Logstash, incluida la lógica condicional, varios pipelines y filtros personalizados para transformaciones de datos complejas. Practicas System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) con código real que ejecutas directamente en el navegador, y un tutor de IA 24/7 responde tus preguntas mientras trabajas en la lección.

¿Necesito experiencia previa para empezar System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry)?

No se requiere experiencia previa. System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) en CoddyKit está estructurado para principiantes hasta estudiantes avanzados, así que puedes empezar aquí o desde el inicio y avanzar a tu ritmo. Esta es la lección 2 de 4.

¿Cuánto tiempo toma la lección «Filtros y pipelines de Logstash»?

La mayoría de las lecciones de CoddyKit toman alrededor de 5–10 minutos. Cada una es compacta e interactiva, así que avanzas constantemente y retomas exactamente por donde dejaste en la web y la app.

¿Puedo escribir y ejecutar código en esta lección de System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry)?

Sí. Cada lección de System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry) incluye un editor de código integrado, así que escribes y ejecutas código real directamente en tu navegador y obtienes retroalimentación instantánea de IA — sin configuración local necesaria.

Todas las lecciones de este curso

  1. Lenguaje de consultas de Elasticsearch (DSL)
  2. Filtros y pipelines de Logstash
  3. Discover y Lens de Kibana
  4. Gestión del ciclo de vida de índices (ILM)
← Volver a System Observability: Logging, Metrics & Tracing (ELK + OpenTelemetry)