I’m forwarding the output as a JSON, but it seems like for some reason, the last word is dropped from the description, even though, I can see it in the message itself. Any ideas what can cause it?
{
"type":"keeper",
"@version":"1",
"keeper_version":"KeeperEnterpriseBridge 15.1.0",
"username":"user@domain.com",
"audit_event_type":"login",
"geo_location":"Tel Aviv, Tel Aviv, IL",
"port":40236,
"@timestamp":"2021-07-15T07:08:05.795Z",
"node_id":"123456",
"keeper_version_category":"ADMIN",
"host":"10.20.30.40",
"description":" User user@domain.com logged in to",
"message":"<110>1 2021-07-15T07:03:07Z 1.2.3.4 Keeper - 4278464624 [Keeper@Commander geo_location=\"Tel Aviv, Tel Aviv, IL\" keeper_version_category=\"ADMIN\" audit_event_type=\"login\" keeper_version=\"KeeperEnterpriseBridge 15.1.0\" username=\"user@domain.com\" node_id=\"123456\"] User user@domain.com logged in to vault"
}
The space at the end of your grok pattern indicate that the GREEDYDATA have to take each value until the last space of the field message. So it also don't take the last word after the space.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.