I want to new create "Message" field by "Thread" + "Loglevel" + "Content".
Please teach me how to do it.
Raw log.
[13172] [INFO] 2021-03-25 09:18:21.150 +0900 : Java class name: org.apache.catalina.startup.Bootstrap; Method name: main; Arguments: start
I use below grok.
%{NOTSPACE:Thread} %{NOTSPACE:Loglevel} %{TIMESTAMP_ISO8601:Time} %{ISO8601_TIMEZONE} %{GREEDYDATA:Content}
Structured Data.
{
  "Loglevel": "[INFO]",
  "Content": ": Java class name: org.apache.catalina.startup.Bootstrap; Method name: main; Arguments: start",
  "Time": "2021-03-25 09:18:21.150",
  "Thread": "[13172]"
}