I am new to logstash and want to extract email IDs and credit card details from files. I am using filebeat to pass log files to logstash and also have setup a config file with the grok patterns. However, I am not able to extract either emailID or credit card. I get this error:
Thanks for your response. I went through the documentation and tried several options. But none of them worked. What I want is to extract email address, credit card along with IP address and other details from the Apache log. Can you please help? My filter is as follows (to extract all details if they exist in one line):
How do I get all details from a single line and if all details are not present, then how do I get just the credit card or email address or the IP address? Below filter also did not work (to extract one detail at a time if they exist):
I compared my grok patterns with that in the documentation several times and nothing seemed out of place. But what troubled me was the output from the log files (they were encoded in a different format). I had been editing the log files in notepad++. So, I decided to process an unedited log file which worked. Opening the log file in notepad, making minor changes to them and running them through grok now worked. Also, adding a new line should be done via a command line (i.e. outside an editor). I hope this helps someone with the same issue.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.