Author: Yucheng Liang
Log Parser is used to parse a log file (.txt
) and export it to a graylog engine for later analysis.
-
Make sure you have the Docker installed.
-
Use the
docker-compose.yml
file to download the images and run it by:$ docker-compose up -d
-
Then you can open a brower and visit
http://127.0.0.1:9000
. You are expected to see the main page of graylog. -
Then follow Graylog Installation to create a input source.
Make sure the log is formatted and matched the pattern inside the log_parser.py
. Then run:
$ python3 log_parser.py [log_file]
It will parses the log and exports them to the graylog cluster. Then you can see your log in the website.