AWS WAF: Further parsing of http_request in logstash

Further to the query: Writing multiline grok
The raw data comes in json, so the NEW line is technically new line but \r\n in the json payload.

"GET /myapp/health HTTP/1.1\\r\\nHost:\\r\\nUser-Agent: Mozilla/5.0 zgrab/0.x\\r\\nAccept: */*\\r\\nAccept-Encoding: gzip\\r\\nX-Forwarded-For:\\r\\n\\r\\n"

Is there an already written http parser for the http_request? Any help would be much appreciated.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.