Can I do an or in a match

(Jack ELK West) #1

Is there a way I can write a grok to do something like:

    match => [ "Message_Data", "File \"C:\\\\Windows\\Prefetch\\DLL" or "New File \"C:\\\\Windows\\Prefetch\\DLL " ]

I don't want to have to write to separate statements for this match since i would just be duplicating everything

(Magnus B├Ąck) #2

Use | to separate the different options (often combined with parentheses):


(system) #3