Every log is exactly the same. I mean the exact same structure because it is log from journalctl.
This is the only way how to parse fields from all systemd logs.
Although, I can't parse the content of "MESSAGE" but I will figure it out
What I don't understand is why I am able to match almost everything in pattern I posted in https://grokdebugger.com/ but I can match only timestamp in kibana dev tools. I tried legoguy1000's pattern in kibana as well, but that didnt work at all
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.