Hello, I don't know why I set the matching specifications, logstash keeps getting error log and cpu usage rate rises rapidly.
The error log is as follows:
[WARN ][logstash.filters.grok ] Timeout executing grok '(.?)"%{GREEDYDATA:timestamp}" fw=%{HOSTNAME:HostName}(.?)user=%{USERNAME:UserName}(.?)%{IP:SourceAddress} op="%{USERNAME:UserLogging}"(.?)user login(.*?)' against field 'message' with value 'Value too large to output (534 bytes)! First 255 chars are:
A single sample log message is as follows:
id=tos time="2008-5-14 06:53:10" fw=TopsecOS pri=6 type=ips recorder=IPSAR proto=tcp src=192.168.3.2 sport=80 dst=192.168.2.2 dport=69000 rule= repeat= msg= appendix= application="qq" op="block" interface= sdev=eth10 ddev=eth11
id=tos time="2008-5-14 06:53:10" fw=TopsecOS pri=6 type=ips recorder=IPSAR proto=tcp src=192.168.3.2 sport=80 dst=192.168.2.2 dport=69000 rule= repeat= msg= appendix= application="qq" op="block" interface= sdev=eth10 ddev=eth11
id=tos time="2008-5-14 06:53:10" fw=TopsecOS pri=6 type=ips recorder=IPSAR proto=tcp src=192.168.3.2 sport=80 dst=192.168.2.2 dport=69000 rule= repeat= msg= appendix= application="qq" op="block" interface= sdev=eth10 ddev=eth11
id=tos time="2008-5-14 06:53:10" fw=TopsecOS pri=6 type=ips recorder=IPSAR proto=tcp src=192.168.3.2 sport=80 dst=192.168.2.2 dport=69000 rule= repeat= msg= appendix= application="qq" op="block" interface= sdev=eth10 ddev=eth11