@@ -61,13 +61,11 @@ logger.deprecation.additivity = false
6161######## Search slowlog JSON ####################
6262appender.index_search_slowlog_rolling.type = RollingFile
6363appender.index_search_slowlog_rolling.name = index_search_slowlog_rolling
64- appender.index_search_slowlog_rolling.fileName = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs\
65- .cluster_name}_index_search_slowlog.json
64+ appender.index_search_slowlog_rolling.fileName = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}_index_search_slowlog.json
6665appender.index_search_slowlog_rolling.layout.type = ESJsonLayout
6766appender.index_search_slowlog_rolling.layout.type_name = index_search_slowlog
6867
69- appender.index_search_slowlog_rolling.filePattern = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs\
70- .cluster_name}_index_search_slowlog-%i.json.gz
68+ appender.index_search_slowlog_rolling.filePattern = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}_index_search_slowlog-%i.json.gz
7169appender.index_search_slowlog_rolling.policies.type = Policies
7270appender.index_search_slowlog_rolling.policies.size.type = SizeBasedTriggeringPolicy
7371appender.index_search_slowlog_rolling.policies.size.size = 1GB
@@ -83,13 +81,11 @@ logger.index_search_slowlog_rolling.additivity = false
8381######## Indexing slowlog JSON ##################
8482appender.index_indexing_slowlog_rolling.type = RollingFile
8583appender.index_indexing_slowlog_rolling.name = index_indexing_slowlog_rolling
86- appender.index_indexing_slowlog_rolling.fileName = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}\
87- _index_indexing_slowlog.json
84+ appender.index_indexing_slowlog_rolling.fileName = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}_index_indexing_slowlog.json
8885appender.index_indexing_slowlog_rolling.layout.type = ESJsonLayout
8986appender.index_indexing_slowlog_rolling.layout.type_name = index_indexing_slowlog
9087
91- appender.index_indexing_slowlog_rolling.filePattern = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}\
92- _index_indexing_slowlog-%i.json.gz
88+ appender.index_indexing_slowlog_rolling.filePattern = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}_index_indexing_slowlog-%i.json.gz
9389appender.index_indexing_slowlog_rolling.policies.type = Policies
9490appender.index_indexing_slowlog_rolling.policies.size.type = SizeBasedTriggeringPolicy
9591appender.index_indexing_slowlog_rolling.policies.size.size = 1GB
@@ -107,38 +103,38 @@ appender.audit_rolling.type = RollingFile
107103appender.audit_rolling.name = audit_rolling
108104appender.audit_rolling.fileName = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}_audit.json
109105appender.audit_rolling.layout.type = PatternLayout
110- appender.audit_rolling.layout.pattern = {\
106+ appender.audit_rolling.layout.pattern = {{ '{' }} \
111107 "@timestamp":"%d{ISO8601}"\
112- %varsNotEmpty{, "node.name":"%enc{% map {node .name }}{JSON }"}\
113- %varsNotEmpty{, " node .id ":" %enc {%map {node .id }}{JSON }"}\
114- %varsNotEmpty{, " host .name ":" %enc {%map {host .name }}{JSON }"}\
115- %varsNotEmpty{, " host .ip ":" %enc {%map {host .ip }}{JSON }"}\
116- %varsNotEmpty{, " event .type ":" %enc {%map {event .type }}{JSON }"}\
117- %varsNotEmpty{, " event .action ":" %enc {%map {event .action }}{JSON }"}\
118- %varsNotEmpty{, " user .name ":" %enc {%map {user .name }}{JSON }"}\
119- %varsNotEmpty{, " user .run_by .name ":" %enc {%map {user .run_by .name }}{JSON }"}\
120- %varsNotEmpty{, " user .run_as .name ":" %enc {%map {user .run_as .name }}{JSON }"}\
121- %varsNotEmpty{, " user .realm ":" %enc {%map {user .realm }}{JSON }"}\
122- %varsNotEmpty{, " user .run_by .realm ":" %enc {%map {user .run_by .realm }}{JSON }"}\
123- %varsNotEmpty{, " user .run_as .realm ":" %enc {%map {user .run_as .realm }}{JSON }"}\
124- %varsNotEmpty{, " user .roles ":%map{user.roles}}\
125- %varsNotEmpty{, " origin .type ":" %enc {%map {origin .type }}{JSON }"}\
126- %varsNotEmpty{, " origin .address ":" %enc {%map {origin .address }}{JSON }"}\
127- %varsNotEmpty{, " realm ":" %enc {%map {realm }}{JSON }"}\
128- %varsNotEmpty{, " url .path ":" %enc {%map {url .path }}{JSON }"}\
129- %varsNotEmpty{, " url .query ":" %enc {%map {url .query }}{JSON }"}\
130- %varsNotEmpty{, " request .method ":" %enc {%map {request .method }}{JSON }"}\
131- %varsNotEmpty{, " request .body ":" %enc {%map {request .body }}{JSON }"}\
132- %varsNotEmpty{, " request .id ":" %enc {%map {request .id }}{JSON }"}\
133- %varsNotEmpty{, " action ":" %enc {%map {action }}{JSON }"}\
134- %varsNotEmpty{, " request .name ":" %enc {%map {request .name }}{JSON }"}\
135- %varsNotEmpty{, " indices ":%map{indices}}\
136- %varsNotEmpty{, " opaque_id ":" %enc {%map {opaque_id }}{JSON }"}\
137- %varsNotEmpty{, " x_forwarded_for ":" %enc {%map {x_forwarded_for }}{JSON }"}\
138- %varsNotEmpty{, " transport .profile ":" %enc {%map {transport .profile }}{JSON }"}\
139- %varsNotEmpty{, " rule ":" %enc {%map {rule }}{JSON }"}\
140- %varsNotEmpty{, " event .category ":" %enc {%map {event .category }}{JSON }"}\
141- }%n
108+ {{ ' %varsNotEmpty{, "node.name":"%enc{%map{node.name}}{JSON}"}' } }\
109+ {{ ' %varsNotEmpty{, "node.id":"%enc{%map{node.id}}{JSON}"}' } }\
110+ {{ ' %varsNotEmpty{, "host.name":"%enc{%map{host.name}}{JSON}"}' } }\
111+ {{ ' %varsNotEmpty{, "host.ip":"%enc{%map{host.ip}}{JSON}"}' } }\
112+ {{ ' %varsNotEmpty{, "event.type":"%enc{%map{event.type}}{JSON}"}' } }\
113+ {{ ' %varsNotEmpty{, "event.action":"%enc{%map{event.action}}{JSON}"}' } }\
114+ {{ ' %varsNotEmpty{, "user.name":"%enc{%map{user.name}}{JSON}"}' } }\
115+ {{ ' %varsNotEmpty{, "user.run_by.name":"%enc{%map{user.run_by.name}}{JSON}"}' } }\
116+ {{ ' %varsNotEmpty{, "user.run_as.name":"%enc{%map{user.run_as.name}}{JSON}"}' } }\
117+ {{ ' %varsNotEmpty{, "user.realm":"%enc{%map{user.realm}}{JSON}"}' } }\
118+ {{ ' %varsNotEmpty{, "user.run_by.realm":"%enc{%map{user.run_by.realm}}{JSON}"}' } }\
119+ {{ ' %varsNotEmpty{, "user.run_as.realm":"%enc{%map{user.run_as.realm}}{JSON}"}' } }\
120+ {{ ' %varsNotEmpty{, "user.roles":%map{user.roles}}' }}\
121+ {{ ' %varsNotEmpty{, "origin.type":"%enc{%map{origin.type}}{JSON}"}' } }\
122+ {{ ' %varsNotEmpty{, "origin.address":"%enc{%map{origin.address}}{JSON}"}' } }\
123+ {{ ' %varsNotEmpty{, "realm":"%enc{%map{realm}}{JSON}"}' } }\
124+ {{ ' %varsNotEmpty{, "url.path":"%enc{%map{url.path}}{JSON}"}' } }\
125+ {{ ' %varsNotEmpty{, "url.query":"%enc{%map{url.query}}{JSON}"}' } }\
126+ {{ ' %varsNotEmpty{, "request.method":"%enc{%map{request.method}}{JSON}"}' } }\
127+ {{ ' %varsNotEmpty{, "request.body":"%enc{%map{request.body}}{JSON}"}' } }\
128+ {{ ' %varsNotEmpty{, "request.id":"%enc{%map{request.id}}{JSON}"}' } }\
129+ {{ ' %varsNotEmpty{, "action":"%enc{%map{action}}{JSON}"}' } }\
130+ {{ ' %varsNotEmpty{, "request.name":"%enc{%map{request.name}}{JSON}"}' } }\
131+ {{ ' %varsNotEmpty{, "indices":%map{indices}}' }}\
132+ {{ ' %varsNotEmpty{, "opaque_id":"%enc{%map{opaque_id}}{JSON}"}' } }\
133+ {{ ' %varsNotEmpty{, "x_forwarded_for":"%enc{%map{x_forwarded_for}}{JSON}"}' } }\
134+ {{ ' %varsNotEmpty{, "transport.profile":"%enc{%map{transport.profile}}{JSON}"}' } }\
135+ {{ ' %varsNotEmpty{, "rule":"%enc{%map{rule}}{JSON}"}' } }\
136+ {{ ' %varsNotEmpty{, "event.category":"%enc{%map{event.category}}{JSON}"}' } }\
137+ {{ '}' } }%n
142138# "node.name" node name from the `elasticsearch.yml` settings
143139# "node.id" node id which should not change between cluster restarts
144140# "host.name" unresolved hostname of the local node
0 commit comments