Filter a field that has different formats

Hi, I am currently filtering logs that normaly return this kind of field (among others):


and my grok for this field is the following:


but for certain machines I got this in the same field:


and my grok for this is the following:


What would be the best aproach to capture both types of fields?

Two groks whas the solution, don't know if is it the more elegant but it works

grok {
                        match => ["message", "%{DATA:some_data}"]
                        match => ["message", "%{DATA:some_data}"]

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.