i am new to ELK. when i onboarded the below log file, it is going to "dead letter queue" in logstash because logstash couldn't able to process the events. I am not sure which type of plugin to use whether KV plugin or CSV plugin because first half of the events are normal and next half is in KV pair. Any help would be appreciated on how to write the filters.
Thank you for the reply. i have changed the filter as per the suggestion. But when i run it in the GROK debugger i am getting compiler error. Below is the filter which i have used.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.