is that mean, i can have 100 expression ? 30 different logs and log format stored in the same file
Yes.
Curiosity do i consider delay, processing 100 expressions ?
Of course, but the grok filter doesn't always test all expressions. It terminates the search as soon as there's a match, so you'll want to sort the expressions in "most likely to match" order.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.