Hi , I am trying to construct grok filter to parse data (tomcat log ) but having issues .
I am using input :
[2017-05-09 16:27:53,156] :|: INFO :|: dfprdsndl22.df.jabodo.com :|: 6771ebd6eb814dc28e479908d542b6f6 :|: [BT:FF, BV:37, BL:en, CC:IN] :|: 103.42.89.250 :|: http://download.filmfanatic.com/index.jhtml?partner=Z1xdm961&theme=01ab12212016&s2=-5658453153796672849&s1=618500 :|: c.m.w.d.m.UnifiedLoggerWrapper :|: - [ET: DLPInfo, IP: 103.42.89.250]
[2017-05-09 16:27:53,409] :|: INFO :|: dfprdsndl22.df.jabodo.com :|: 6771ebd6eb814dc28e479908d542b6f6 :|: [BT:FF, BV:37, BL:en, CC:IN] :|: 103.42.89.250 :|: http://download.filmfanatic.com/index.jhtml?partner=Z1xdm961&theme=01ab12212016&s2=-5658453153796672849&s1=618500 :|: c.m.w.d.m.UnifiedLoggerWrapper :|: - [ET: SplashPageServed, IP: 103.42.89.250]
[2017-05-09 16:27:53,513] :|: INFO :|: dfprdsndl22.df.jabodo.com :|: :|: [BT:FF, BV:53, BL:en, CC:US] :|: 96.236.136.65 :|: http://puzzlegamesdaily.dl.myway.com/blank.jhtml :|: c.m.w.d.m.UnifiedLoggerWrapper :|: - [ET: BlankPageServed, IP: 96.236.136.65]
[2017-05-09 16:27:53,523] :|: INFO :|: dfprdsndl22.df.jabodo.com :|: f60bd13c2c154325b35edfa737166a15 :|: [BT:CHROME, BV:53, BL:en, CC:US] :|: 169.241.55.127 :|: :|: c.m.w.d.m.UnifiedLoggerWrapper :|: - [ET: ToolbarDetect, IP: 169.241.55.127]
[2017-05-09 16:27:54,011] :|: INFO :|: dfprdsndl22.df.jabodo.com :|: :|: [BT:CHROME, BV:57, BL:en, CC:US] :|: 98.93.68.71 :|: :|: c.m.w.d.m.UnifiedLoggerWrapper :|: - [ET: PageView, IP: 98.93.68.71]
Trying to get parse data in the format of
timestamp :|: level :|: hostname :|: requestid :|:browser key :|: requestip :|: url :|: client ip
What grok filter will be helpful for this ?
Thanks,
Nikhil