Hi. I am struggling to write a grok pattern for Modsecurity Logs from the apache error log. I have included a sample log and the grok pattern. I isolated the timestamp creation which works on its own. However the rest works on the debugger but not in logstash. If anyone could help I would appreciate it.
Thank you for responding. That's interesting. Would it be okay if I posted a screenshot of my configuration file? I would just copy the file but it's on a VM and difficult to get. Maybe it's something I'm missing? I can get the timestamp working but none of the rest. Anything else it could be?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.