Grok Filter

I have event from Acces Point Dlink.
I can parse some events but for this type I need your help:


Could you help me?
Thanks a lot


It looks like a comma-separated list of key-value pairs. You can use the kv filter in Logstash to parse this. Here's an example of how you might do it:

filter {
  kv {
    source => "message"
    field_split => ","
    value_split => "="
    trim_key => " "
    trim_value => " "
    remove_char_value => "\""


Thanks for your feedback.
If I use this configuration, I only have one line with no spaces in it.
How can I edit th grok match?
thanks a lot

At begging of the line, you have <6>1707130951, you can use grok or dissect and then apply KV which yago82 mentioned. Dissect is much easier.

    dissect {
      mapping => {
        "message" => "<%{procid}>%{sessionid},%{msg}"

Change source
kv {
source => "msg"...

1 Like

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.