Help with grok for logfile


(Dhiraj Khanna) #1

I am very new to the ELK stack and have been trying to look at some tutorials to get me started. Would appreciate if someone could point me in the right direction for ingesting the following type of logs. I assume that I would need to put together a grok filter but need a little helping hand :-

2017-07-07 00:00:00,021 STARTING REPORT AT Fri Jul 07 00:00:00 IST 2017
** Jul 07 00:00:00 **
** Jul 07 00:00:00 ** Alerts
** Jul 07 00:00:00 ** Totals (R/P/H) 0 | 0 | 0
** Jul 07 00:00:00 ** Received (Recent) 0 | 0.00 /sec
** Jul 07 00:00:00 ** Parsed (Recent) 0 | 0.00 /sec
** Jul 07 00:00:00 ** Handled (Recent) 0 | 0.00 /sec
** Jul 07 00:00:00 **
** Jul 07 00:00:00 ** Tracks (MSCT)
** Jul 07 00:00:00 ** Totals (In/Ok/Bad) 13384470 | 13223515 | 160955
** Jul 07 00:00:00 ** Totals (Ok/Parse) 13223515 | 13223515
** Jul 07 00:00:00 ** Totals (U/D/Discard) 7776339 | 855745 | 4591431
** Jul 07 00:00:00 ** Totals (Ready/Sent) 8632084 | 8632084
** Jul 07 00:00:00 ** Accepted (Recent) 6757 | 56.31 /sec
** Jul 07 00:00:00 ** Parsed (Recent) 6757 | 56.31 /sec
** Jul 07 00:00:00 ** Updated (Recent) 4307 | 35.89 /sec
** Jul 07 00:00:00 ** Dropped (Recent) 309 | 2.57 /sec
** Jul 07 00:00:00 ** Discard (Recent) 2141 | 17.84 /sec
** Jul 07 00:00:00 ** Sent (Recent) 4616 | 38.47 /sec
** Jul 07 00:00:00 **
** Jul 07 00:00:00 ** Tracks (Session)
** Jul 07 00:00:00 ** Data Source (Multicast) 0 | 0.00 /sec
** Jul 07 00:00:00 ** Data Source (Broadcast) 0 | 0.00 /sec
** Jul 07 00:00:00 ** Data Source (TCP) 4645 | 38.71 /sec
** Jul 07 00:00:00 ** Totals (R/P/H) 9331552 | 9331552 | 9331552
** Jul 07 00:00:00 ** Totals (U/D) 7950395 | 1381157
** Jul 07 00:00:00 ** Received (Recent) 4836 | 40.30 /sec
** Jul 07 00:00:00 ** Parsed (Recent) 4836 | 40.30 /sec
** Jul 07 00:00:00 ** Updated (Recent) 4363 | 36.36 /sec
** Jul 07 00:00:00 ** Dropped (Recent) 473 | 3.94 /sec
** Jul 07 00:00:00 ** Handled (Recent) 4836 | 40.30 /sec
** Jul 07 00:00:00 ** Last Received -
** Jul 07 00:00:00 **
** Jul 07 00:00:00 ** Commands
** Jul 07 00:00:00 ** Totals (R/P/H) 2917 | 2901 | 0
** Jul 07 00:00:00 ** Received (Recent) 2 | 0.02 /sec
** Jul 07 00:00:00 ** Parsed (Recent) 2 | 0.02 /sec
** Jul 07 00:00:00 ** Handled (Recent) 0 | 0.00 /sec
** Jul 07 00:00:00 **

My attempt at filtering are not even worth mentioning, but this is what I have tried so far %{TIMESTAMP_ISO8601:timestamp}%{SPACE}%{GREEDYDATA:message}


(Joseph Johney) #2

try experimenting your filters using Grok Debugger Grok debugger


(system) #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.