However, I am getting a grok prase failure, I am not sure what the problem is. cant seem to pin point the pattern that is causing the problem. Any thoughts/comments would be appreciated.
If I copy paste your message field and grok patter into the window I get this result. You can see that the first two patterns matched, but nothing after that did. It looks to be breaking around the SYSLOGBASE tag.
It actually still showed as not fully matching for me.
If you look at your test line you can see that it has a space right after the timestamp, I don't see that on yours.
Add a space between the colon separating the two expressions.
Before:
%{SYSLOGTIMESTAMP:syslog_timestamp}:%{GREEDYDATA:syslog_message}
After:
%{SYSLOGTIMESTAMP:syslog_timestamp} : %{GREEDYDATA:syslog_message}
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.