logstash 中可以设置字段的类型为integer,string,float,boolean
filter {
grok {
match => {"message" => "(?<client_ip>%{USERNAME}) - - \[(?<time>[0-9a-zA-Z/: +]+)\] \"%{NOTSPACE:method} %{NOTSPACE:url} %{NOTSPACE}[\"] %{INT:status} %{INT} [\"]%{USERNAME}[\"] [\"](?<http_user_agent>.*)[\"]"}
}
mutate {
convert => ["status", "integer"] #修改字段类型
}
}