I'm using docker labels to filter for certain messages and to apply the appropriate grok patterns.
The patterns work when I test them with the grok debugger but I'm getting _grokparsefailure when I use them in this configuration:
Your log entry does not have two timestamps. You should blockquote your log entries, patterns, and second configuration the same way you blockquoted the first configuration (i.e. indent by 4 spaces). Otherwise we have to guess which characters in your pattern have been consumed as markdown by spotting where your text is in italics etc.
The following works, assuming you need to consume timestamps in two different formats. Not sure whether you want to use the overwrite option or not.
Thank you for your reply and the explanation!
This pattern is working fine when applied within the Grok Debugger but is still causing _grokparsefailure when applied within logstash.conf:
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.