My_logstash_filter.conf file
filter {
grok {
match => [
"message", "(?[A-Z_A-Z_A-Z]{10,14})",
"message", "(?[A-Z:A-Z:A-Z]{10,14})",
"message", "(?[A-Z]{4})" ]
}
}
These three fields never display at a time for every message. Any one of them show and other two of them are hide.
Status                                         Operator                                         Loglevel
SENT                                                    --                                                       --
--                                                      GP                                                   --
--                                                      --                                                      INFO
But I need like this:
Status                                         Operator                                         Loglevel
SENT                                                               Blink                                                WARN
FAIL                                                                 GP                                                   INFO
ERROR                                                            GP                                                    INFO
but not show status field.
my all status will be (10~14)characters of these
"GW_IGNORED
GW_IN_PROGRESS
GW_PENDING
GW_UNREACHABLE
TELCO_ERROR
TELCO_SENT"
How can I add status filed in my Logstash filters Grok?
Thanks