Hi, I have the following text below that I'm trying to parse just the IP and username. I've tried adding all the text prior to the IP but still nothing. Even if I just put 1.1.1.1 into the Grok Debugger and %{IP} as the filter, I get nothing so I think there's something very basic I'm missing and could use some help.
Gateway user authentication succeeded. Login from:119.146.12.113, Source region: US, User name: admin, Auth type: profile, Client OS version: Microsoft Windows 10 Enterprise , 64-bit.
Sorry for another question but why doesn't this work in the grok debugger site (https://grokdebug.herokuapp.com)? I thought that was were to go to test your patterns.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.