Are you sure that you want to use grok? I think Dissect is better here. Grok uses regular expressions, while dissect looks at delimiters. This makes Dissect faster. It looks like these logs share the same delimiters ("[" & ":" & "]") . Please let me know what you think,
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.