Sorry, I wrote my question in a very bad way....
Let me try again:
I have some logs coming from a custom software, nothing commercial.
An example is this one:
[HttpServer] - Conn=86734174 - GET http://o1bp.farm.mediaset.it/farmunica/2018/03/169375_1621a76728b965/hlsnrcenc/l9/401.ts - 304 - 81.74.234.162:13784 - 0 etag="15acca2c9e8" - 8
I wrote a grok filter to extract all the information I need from the log, for example the etag but even some information from the url itself, for example the number 401 which I have named "chunkID".
So far so good, my grok filter works quite well and I have all the info I need.
If you note some of the info I have extracted came from the url "http://o1bp.farm.mediaset.it/farmunica/2018/03/169375_1621a76728b965/hlsnrcenc/l9/401.ts" and here is the problem.
I need the info "inside" the url in different fields but the url itself in a separate filed.
For example, my grok filter is capable to extract these values:
"bytesSend": 534860,
"response": 200,
"syslogtag": "origin:",
"msg": " [HttpServer] - Conn=8610516 - GET http://o1bp.farm.mediaset.it/farmunica/2018/03/169375_1621a76728b965/hlsnrcenc/l9/401.ts - 200 - 81.74.228.136:46556 - 534860 etag=\"1621b45b540\" - 11",
"etag": "1621b45b540",
"@version": "1",
"sysloghost": "ms-origin03",
"appname": "origin",
"protocol": "http",
"tags": [
"origin-geoip"
],
"path": "/tmp/logExample.log",
"clientPort": 46556,
"nameServer": "o1bp.farm.mediaset.it",
"severity": "INFO",
"hlsLevel": "l9",
"hlsVideoChunk": 401,
"@timestamp": "2018-04-06T09:59:58.144Z",
"connectionId": 8610516,
"geoip": {
"country_code3": "IT",
"country_name": "Italy",
"continent_code": "EU",
"location": {
"lon": 12.1097,
"lat": 43.1479
},
"timezone": "Europe/Rome",
"ip": "81.74.228.136",
"longitude": 12.1097,
"country_code2": "IT",
"latitude": 43.1479
},
"clientIp": "81.74.228.136",
"connDropped": "false",
"facility": "local2",
"uriType": "hls",
"responseTime": 11,
"method": "GET",
"cmsTag": "hlsnrcenc",
"host": "foxs-MacBook-Pro.local"
How could add the relative url "/farmunica/2018/03/169375_1621a76728b965/hlsnrcenc/l9/401.ts" ?
With a second grok filter?
Hope is more clear now.
Anyway, thanks for your help.
Regards,
S.