Hi everyone I'm new to Elastick Stack, I set grok custom pattern using RegEx: MODULE_NAME (?:((?<=[\[])\/\S[^\]]+))
the problem is it's optional pattern so I want the "module_name" field to be empty instead of showing "_grokparsefailure" tag
logstash filter:
thanks Cad for your replay, I already tested that pattern with grok debugger and ruby before asking
the problem in this case (pattern)? is module_name field alwayse return empty ""
in two cases, when [/whatever] exist and not
What is the look of the data you want to get ? can you share us example ?
Because when you share us the value [/watever] i understand that only watever can change. Is that true ?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.