Dynamically add GROK rules to logstash


(vineeth mohan-2) #1

Hi ,

I have various GROK rules which will identify mark various log lines based
on certain rules.
Currently on adding a new GROK rule , we need to restart logstash.
Is there a way to do it , without restarting logstash , i.e. dynamically
change or add the GROK conf file.

Thanks
Vineeth

--
You received this message because you are subscribed to the Google Groups "elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email to elasticsearch+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/elasticsearch/CAGdPd5me_vRn9z0cpGao4iTTZqp3GRoiXLh7sKPjDAR8T66sLQ%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.


(Mark Walkom) #2

Nope, you need to restart logstash for it to pick up the new config.

Regards,
Mark Walkom

Infrastructure Engineer
Campaign Monitor
email: markw@campaignmonitor.com
web: www.campaignmonitor.com

On 12 August 2014 13:52, vineeth mohan vm.vineethmohan@gmail.com wrote:

Hi ,

I have various GROK rules which will identify mark various log lines based
on certain rules.
Currently on adding a new GROK rule , we need to restart logstash.
Is there a way to do it , without restarting logstash , i.e. dynamically
change or add the GROK conf file.

Thanks
Vineeth

--
You received this message because you are subscribed to the Google Groups
"elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an
email to elasticsearch+unsubscribe@googlegroups.com.
To view this discussion on the web visit
https://groups.google.com/d/msgid/elasticsearch/CAGdPd5me_vRn9z0cpGao4iTTZqp3GRoiXLh7sKPjDAR8T66sLQ%40mail.gmail.com
https://groups.google.com/d/msgid/elasticsearch/CAGdPd5me_vRn9z0cpGao4iTTZqp3GRoiXLh7sKPjDAR8T66sLQ%40mail.gmail.com?utm_medium=email&utm_source=footer
.
For more options, visit https://groups.google.com/d/optout.

--
You received this message because you are subscribed to the Google Groups "elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email to elasticsearch+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/elasticsearch/CAEM624ZVBBVvUerDpqNiV0O%2B%3DxortMDEznF5g1-rqDypw9BMog%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.


(system) #3