Hi Guys,
Can anyone help me to do the following configuration to work as expected.
I'm trying to create the separate field for apache response code status using grok filter but it print IP address first two octect.
Grok Filter configuration:
filter {
grok {
match => { "message" => "%{COMBINEDAPACHELOG}" }
}
grok {
match => { "message" => "%{URIPROTO}://%{HOSTNAME:domain}" }
}
grok {
match => { "message" => "%{NUMBER:response}" }
}
}
I'm receiving output like below,
response 192.168