I would like to know if you have a link or a step by step guide on how to add more format for filebeat? Looking to add more format for filebeat apache module. Latest version.
Provided Grok expressions do not match field value: [172.243.17.195, 192.88.135.13, 172.31.40.168, 172.31.40.168 127.0.0.1 - - [13/Jun/2019:19:50:02 +0000] "GET
Notice the grok processor in both these pipelines.
If you want to add more formats to this processor definition, you will need to define new lines in the patterns array. For this you will want to make a pull request to the elastic/beats repository. Follow the contribution guidelines listed here: https://www.elastic.co/guide/en/beats/devguide/current/beats-contributing.html.
Turn out the problem was related to wrong clasification. My previous exampe was flag as Apache errors log and not Access. I Made the changes and now it fix. But I still have an issue with another format. I don't understand what missing.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.