I have Elasticsearch, Logstash and Kibana all versions 5.6.2 configured and running on Windows 2012 R2. Some sample data I am trying to parse is: (filtered for sensitive info)
2017-09-18 00:00:01 Local4.Debug 00.00.00.0 Sep 18 2017 00:00:01: %ASA-0-000000: UDP request discarded from 00.00.00.00/00000 to COVERT:000.000.000.000/0000
the following is my grok pattern in my logstash config file reading from a .txt file:
grok {
match => { "message" => "%{TIMESTAMP_ISO8601:timestamp}%{SPACE}Local4.%{LOGLEVEL}%{SPACE}%{IP}%{SPACE}%{CISCOTIMESTAMP}: %%{CISCOTAG}%{GREEDYDATA}" }
}
It parses in the grok debugger but in Kibana the whole entry shows up as message, not separate fields. It also auto-generates the time stamp to be current but I'm reading logs that are 24 hours old. Not sure what I have going on.