refactor syslog filter
This commit is contained in:
parent
e7b034b960
commit
68c4233e33
|
@ -1,14 +1,14 @@
|
||||||
filter {
|
filter {
|
||||||
if [type] == "syslog" {
|
|
||||||
grok {
|
grok {
|
||||||
match => { "message" => "%{SYSLOGTIMESTAMP:timestamp} %{SYSLOGHOST:hostname} %{DATA:program}(?:\[%{POSINT:pid}\])?: %{GREEDYDATA:message}" }
|
match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
|
||||||
add_field => [ "received_at", "%{@timestamp}" ]
|
add_field => [ "received_at", "%{@timestamp}" ]
|
||||||
add_field => [ "received_from", "%{host}" ]
|
add_field => [ "received_from", "%{host}" ]
|
||||||
|
add_field => [ "program", "%{syslog_program}" ]
|
||||||
}
|
}
|
||||||
syslog_pri { }
|
syslog_pri { }
|
||||||
date {
|
date {
|
||||||
match => [ "timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]
|
match => [ "syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]
|
||||||
}
|
}
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue