How do I break E0802 into E and 0802?
http://grokdebug.herokuapp.com/
E0802 05:01:29.979775 30003 logging.cc:121] stderr will be logged to this file.
%{NOTSPACE:log_level} %{NOTSPACE:log_time} %{NOTSPACE:log_threadid} %{NOTSPACE:log_file}:%{NOTSPACE:log_line}] %{GREEDYDATA:log_msg}
Badger
August 6, 2018, 11:04pm
2
Use grok.
grok { match => { "log_level" => "(?<e>.)%{NUMBER:foo}" } }
Badger
August 7, 2018, 12:04am
3
Wait, what did you do to make everything an array of arrays? I would have expected that to get parsed as (in rubydebug terms)
"log_level" => "E0802"
"log_time" => "05:01:29.979775"
etc.
system
(system)
Closed
September 4, 2018, 12:14am
4
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.