Grok Output to comma separated


(Vivek Raj) #1

Hi Everyone,

How can i convert my Grok output to comma separated

My Grok Pattern (Nginx access log)

%{IPORHOST:clientip} %{NGUSER:ident} %{NGUSER:auth} [%{HTTPDATE:timestamp}] \ "(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|-)" %{NUMBER:response} (?:%{NUMBER:bytes}|-) %{GREEDYDATA:message}

Expected Output

clientip,ident,auth,timestamp,verb,request,httpversion,response,bytes,message

Please help to build logstash config here.

Thanks
Viv


(Jymit Singh Khondhu) #2

Hi,

Have a ganders at the CSV output plugin: https://www.elastic.co/guide/en/logstash/current/plugins-outputs-csv.html


(system) #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.