Hello!
I have have a problem with grok getting full message from log file. Can you please help me?
Log message:
2019-10-29 19:27:21.779+02:00 [ 27] INFO - State has changed: Rule: Recording FPS, Counter: \VideoOS Recording Server Device(test 2 [64542b95-e5e9-4800-8f10-3ee8ba09773d])\Media/sec perc, Before: Critical, now: Normal
Changes based on data: 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 2116,678,
Grok pattern:
%{TIMESTAMP_ISO8601:system.syslog.timestamp} [ %{SPACE} %
{NUMBER:milestone_lognum}] %{LOGLEVEL:milestone_loglevel} %{SPACE} - %{GREEDYDATA:milestone_message}
Structured data result:
{
"system": {
"syslog": {
"timestamp": "2019-10-29 19:27:21.779+02:00"
}
},
"milestone_lognum": "27",
"milestone_loglevel": "INFO",
"milestone_message": "State has changed: Rule: Recording FPS, Counter: \VideoOS Recording Server Device(test 2 [64542b95-e5e9-4800-8f10-3ee8ba09773d])\Media/sec perc, Before: Critical, now: Normal "
}