I am trying to parse and store a lot of syslog data, currently RHEL syslog + log4j output from Spring apps (Constraint is it has to come via rsyslog for now).
My input is :
port => 514
type => "syslog"
and my grok filter is :
In my logstash.stdout, AFAIK I am matching OK as my "match1 greedy" tag has been added, yet I still get lots of parsefailures
Correct me if I am wrong but I am expecting, if I get the right matches in this grok, I shouldn't be seeing any parsefailures or anything at all in logstash.stdout ?
I'm using logstash-1.4.2-1_2c0f5a1.noarch on RHEL 6.6