Logstash version: 7.0.1
Given filename => "EUI106_occurances", I want to have code => "EUI106".
The following grok parse filter doesn't work:
filter{
grok {
match => { "filename", "%{POSTFIX_QUEUEID:code}" }
}
}
Logstash version: 7.0.1
Given filename => "EUI106_occurances", I want to have code => "EUI106".
The following grok parse filter doesn't work:
filter{
grok {
match => { "filename", "%{POSTFIX_QUEUEID:code}" }
}
}
grok {
match => ["filename","%{GREEDYDATA}/%{GREEDYDATA:code}\_occurances"]
}
or
grok {
match => ["filename","%{GREEDYDATA}/%{GREEDYDATA:code}"]
}
mutate {
gsub => ["code", "_occurances", ""]
}
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.