Hello All,
I am tying to create a index below are the config file and sample log. Please let me if anything wrong in my config file.
Thanks for your help!
Log :
2017-10-02 01:00:02,782 DEBUG [com._360commerce.foundation.util.DBConnection] SQL = SELECT VAL_TYPE.VALTYPEID, VAL_TYPE.VALIDATORNAME, VAL_TYPE.CLASS, VAL_TYPE.PACKAGE FROM PARM_VALIDATOR, VAL_TYPE WHERE PARM_VALIDATOR.VALTYPEID = VAL_TYPE.VALTYPEID AND PARM_VALIDATOR.PARMID = ?
2017-10-02 01:00:02,782 DEBUG [com._360commerce.foundation.util.DBPreparedStatement] PreparedStatment variables = Count = 1
Variables = 2541,
Config File:
input {
file {
path => "home/gprasad/btest.log"
#type => "LOG"
start_position => "beginning"
codec => multiline
{
pattern => "^\A%{TIMESTAMP_ISO8601}"
negate => true
what => previous
}
}
}
filter{
mutate
{
gsub => ["message", "\n", ""]
gsub => ["message", "\r", ""]
gsub => ["message", "\t", ""]
}
grok {
match => [ "message", "%{TIMESTAMP_ISO8601:Date} *%{LOGLEVEL:Type} [%{DATA:Application}] %{GREEDYDATA:Message}" ]
overwrite => [ "message" ]
}
date {
match => [ "Date","[yyyy-MM-dd HH:mm:ss,zzz]"]
target => "Date"
}
}
output
{
#stdout{}
stdout {codec => rubydebug}
elasticsearch
{
hosts => "localhost"
index => "kp-log-1296-bo-index1"
}
}
Error:
{
"path" => "home/gprasad/btest.log",
"Type" => "DEBUG",
"@timestamp" => 2017-11-02T09:32:57.906Z,
"Message" => "SQL = SELECT VAL_TYPE.VALTYPEID, VAL_TYPE.VALIDATORNAME, VAL_TYPE.CLASS, VAL_TYPE.PACKAGE FROM PARM_VALIDATOR, VAL_TYPE WHERE PARM_VALIDATOR.VALTYPEID = VAL_TYPE.VALTYPEID AND PARM_VALIDATOR.PARMID = ?",
"@version" => "1",
"host" => "oc1008401175.ibm.com",
"message" => "2017-10-02 01:00:02,782 DEBUG [com._360commerce.foundation.util.DBConnection] SQL = SELECT VAL_TYPE.VALTYPEID, VAL_TYPE.VALIDATORNAME, VAL_TYPE.CLASS, VAL_TYPE.PACKAGE FROM PARM_VALIDATOR, VAL_TYPE WHERE PARM_VALIDATOR.VALTYPEID = VAL_TYPE.VALTYPEID AND PARM_VALIDATOR.PARMID = ?",
"Application" => "com._360commerce.foundation.util.DBConnection",
"Date" => "2017-10-02 01:00:02,782",
"tags" => [
[0] "_dateparsefailure"
]
}