My grok filter works as a charm and all logs go into groksuccess.
However, when I deliberately change the grok filter not to match my entries I can see them in /var/log/logstash/logstash-plain.log being tagged with _grokparsefailure and yet they don't go into my grokfailures file.
Hi @Badger, yes the file didn't existed and I created it. I also removed the file_mode and again no joy. Again, as I said the funny thing is that file groksuccess receives all the logs but whey they are tagged with _grokparsefailure they just won't go into file grokfailures
This is a single entry when I alter the regex to fail to match the logs and as you can see the _grokparsefailure tag is in there
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.