Hello All,

could you please help us to get the desire out put my logs usign the logstash groke filter

My Logformat id :"Apr 17 15:20:01 wiki-jira CROND[8769]: (root) CMD (/usr/lib64/sa/sa1 1 1)"

I want get the out as " CMD (/usr/lib64/sa/sa1 1 1)" ..

I tried the several ways but no luck to me .. Pleasae suggest us how to do ?


Have you looked at the syslog example in the documentation?

And try this!
I came up with that in 1 min. You can use the mutate filter to remove fields

