Grok pattern need


(nagaraj) #1

Hi All,

Could you share your thought to get the exact grok pattern for the below content,

log file --> "ServerManager~31bf3856ad364e35~amd64~~6.3.9600.16384, Remote Parent: IIS-HttpErrors, Intended State: Staged"

so the grok pattern how will write,

I want message => "IIS-httpErrors" feet in to elasticsearch

Thanks,
Nagaraj,


(Sebastián Greco) #2

Hi,

There are infinite ways of filtering this log...most likely mine is not the better one, but I hope it helps you anyways.

^ServerManager~[^:]+:\s(?<yourlabelhere>[\w-]+)[^:]+:\sStaged$

Regards!


(system) closed #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.