My_logstash_filter.conf file
filter {
grok {
match => [
"message", "(?[A-Z_A-Z_A-Z]{10,14})",
"message", "(?[A-Z:A-Z:A-Z]{10,14})",
"message", "(?[A-Z]{4})" ]
}
}
These three fields never display at a time for every message. Any one of them show and other two of them are hide.
Status Operator Loglevel
SENT -- --
-- GP --
-- -- INFO
But I need like this:
Status Operator Loglevel
SENT Blink WARN
FAIL GP INFO
ERROR GP INFO
but not show status field.
my all status will be (10~14)characters of these
"GW_IGNORED
GW_IN_PROGRESS
GW_PENDING
GW_UNREACHABLE
TELCO_ERROR
TELCO_SENT"
How can I add status filed in my Logstash filters Grok?
Thanks