Hey, would really appreciate some help debugging this.
Example log line: 2019-02-24 17:58:30,396 INFO [i.b.logging.LoggingComponent] [] [] [] : The log message
Parse rule that succeeds in the Grok debugger but fails for all logs in logstash: %{DATE:date} %{TIME:timestamp} %{LOGLEVEL:level} \[(%{DATA:logger})?\] %{GREEDYDATA:content}
Parse rule that succeeds on for all logs on both: %{DATE:date} %{TIME:timestamp} %{LOGLEVEL:level} %{GREEDYDATA:content}
Logstash is being fed by filebeat with a multiline configuration to handle stacktraces.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.