msg: Malware/Virus detected - Rtf.Exploit.CVE_2017_11882-6584355-0:Message denied for delivery:Announcement: Holiday Tomorrow
This is where i'm figuring out how to match the "Announcement: Holiday Tomorrow" or "Announcement Holiday Tomorrow" part of the log. It can have colon or not. At the moment i don't have the right pattern. I'm new to logstash.
grok {
match {
"msg" => "%{[^:]+$}:%{GREEDYDATA:headerSubject}"
}
}
Actually it will not be the same format. but i got the idea from you. I modified my log to have a "Subject - " part instead. so logstash config can be simple
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.