Hi @hta , try the following grok pattern
filter {
grok {
id => "name school grok filter"
match => { 'message' => '^.*name=\'%{WORD:name}\'.*school=\'%{WORD:school}\''}
}
}
it gets the name and the school from the message.
Hi @hta , try the following grok pattern
filter {
grok {
id => "name school grok filter"
match => { 'message' => '^.*name=\'%{WORD:name}\'.*school=\'%{WORD:school}\''}
}
}
it gets the name and the school from the message.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.