Not sure exactly if this is what you need/want kind of new to this myself.
But if you need a parsing string for this type of message so logstash can
identify some specific parts from it. There is a very good site called http://grokdebug.herokuapp.com/ where you can put the line to parse and
then test the pattern line to test so you can see if the parsing is
working. It has helped me quite a lot.
For your specific part of the message you could try this line:
(?[^|]+)|(?[^|]+)|(?[^|]+)|(?[^|]+)|(?[^|]+)|(?[^|]+)|(?[^|]+)|(?.*)
This will put the "0" in field1, "TestCompany" in field2 etc...And pass
these as fields in elasticsearch.
Hope this helps,
s.r./F
On Friday, February 14, 2014 10:56:30 PM UTC+1, san wrote:
I have the following message to parse:
<6> Jan 9 07:19:26 w2k8r233110
0|TestCompany|Analytics|8.0.1310|TestSignature|This is test
message|Medium|src=10.100.1.100
Here the actual message part is:
0|TestCompany|Analytics|8.0.1310|TestSignature|This is test
message|Medium|src=10.100.1.100
Could someone help me out in creating a JSON from this message?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.