Hi,
For the following message i using the specified grok pattern but in the output i get grok faild i tried using the grok constructed, which is not favoring me
In Message :
<2018-01-31 00:00:11>,<896> < INFO > < [STDOUT] > <(http-WEB0001VR%2F10.351.100.19-1000-15) > < 00:00:11,896 >
<[com.test.tst.connectivity.fddInvoker]> < INFO > - < TVS MSG Response > < [ CUSTOMER,PARTY.INFO/I/PROCESS///,***************//IN00111521,5269453 ] >
<2018-02-01 00:00:11>, < 455 > < ERROR > < [STDOUT] > < (http-WEB0001VR%2F10.351.100.19-1000-15) > < 00:00:11,896 >
< [com.test.tst.connectivity.fddInvoker] > < INFO > - < TVS MSG Response > < [ PART,PARTY.INFO/I/PROCESS///,***************//IN00111521,984453 ] >
LOG FORMAT - HIGH LEVEL:
< TIME STAMP > < , > < ID > < ERROR (OR) INFO > <[STDOUT]> <SERVER & IP > <DURATION & ID > <COM.ID> <INFO (OR) ERROR > <SERVICE RESPONSE/REQUEST> <RESPONSE MESSAGE/ REQUEST MESSAGE>
Grok pattern:
match => [ "message", "%{TIME:time} %{LOGLEVEL:level} [(?[^]]+)] ((?[^)]+)) %{GREEDYDATA:message}" ]
Any idea about this ??
Thanks in advance
Vicky