Добрый день!
Прошу помочь разобрать лог печати из windows. За ранее извиняюсь, т.к. дуб дубом в grok
[2021-08-19T23:14:41,726][WARN ][logstash.outputs.elasticsearch][main][7a22c627e1accad82d7e582d6ff4b94f3fb25a00d651310816b6db7e5757d6f1] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"win_print-logs-19.08.2021", :routing=>nil}, {"winlog"=>{"channel"=>"Microsoft-Windows-PrintService/Operational", "process"=>{"thread"=>{"id"=>12372}, "pid"=>3692}, "user"=>{"identifier"=>"S-1-5-21-3399346512-758631369-2990822830-15962", "name"=>"i.ivanov", "type"=>"User", "domain"=>"AAA"}, "computer_name"=>"MS-307-2.AAA.RT.LOCAL", "opcode"=>"Операция очереди успешно выполнена", "provider_name"=>"Microsoft-Windows-PrintService", "provider_guid"=>"{747ef6fd-e535-4d16-b510-42c90f6873a1}", "user_data"=>{"Param5"=>"WF-M5690 Series(Сеть) (Копировать 1)", "Param4"=>"\\\\MS-307-2", "Param3"=>"i.ivanov", "Param2"=>"Печать документа", "Param8"=>"1", "Param6"=>"EP065BC7:WF-M5690 SERIES", "Param7"=>"7284", "xml_name"=>"DocumentPrinted", "Param1"=>"169"}, "keywords"=>["Задание печати документа", "Классическое событие очереди"], "api"=>"wineventlog", "record_id"=>3251, "event_id"=>"307", "task"=>"Печать документа"}, "event"=>{"provider"=>"Microsoft-Windows-PrintService", "code"=>"307", "created"=>"2021-08-19T23:14:39.952Z", "kind"=>"event", "action"=>"Печать документа"}, "tags"=>["win_print", "win_print", "beats_input_codec_plain_applied", "_grokparsefailure"], "ecs"=>{"version"=>"1.10.0"}, "host"=>{"os"=>{"kernel"=>"10.0.19041.1052 (WinBuild.160101.0800)", "build"=>"19042.1052", "type"=>"windows", "platform"=>"windows", "version"=>"10.0", "name"=>"Windows 10 Enterprise", "family"=>"windows"}, "id"=>"c3d5f491-5268-4d3d-bc36-8aad2de6cfec", "ip"=>["10.0.82.2"], "name"=>"MS-307-2.AAA.RT.LOCAL", "mac"=>["6c:4b:90:6b:a4:62"], "hostname"=>"MS-307-2", "architecture"=>"x86_64"}, "message"=>"Документ 169, Печать документа, которым владеет i.ivanov на \\\\MS-307-2, был распечатан на WF-M5690 Series(Сеть) (Копировать 1) через порт EP065BC7:WF-M5690 SERIES. Размер в байтах: 7284. Страниц напечатано: 1. Действий пользователя не требуется.", "@timestamp"=>2021-08-19T23:14:38.248Z, "@version"=>"1", "log"=>{"level"=>"сведения"}, "agent"=>{"id"=>"e54412be-f63c-46e1-bce7-d98a55a25b1f", "type"=>"winlogbeat", "ephemeral_id"=>"2034feeb-a43b-413c-a197-859bcfc247d7", "version"=>"7.14.0", "name"=>"MS-307-2", "hostname"=>"MS-307-2"}}], :response=>{"index"=>{"_index"=>"win_print-logs-19.08.2021", "_type"=>"_doc", "_id"=>"NrqxYHsBTAwmix39-Veb", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [host] of type [text] in document with id 'NrqxYHsBTAwmix39-Veb'. Preview of field's value: '{hostname=MS-307-2, os={build=19042.1052, kernel=10.0.19041.1052 (WinBuild.160101.0800), name=Windows 10 Enterprise, type=windows, family=windows, version=10.0, platform=windows}, ip=[10.0.82.2], name=MS-307-2.AAA.RT.LOCAL, id=c3d5f491-5268-4d3d-bc36-8aad2de6cfec, mac=[6c:4b:90:6b:a4:62], architecture=x86_64}'", "caused_by"=>{"type"=>"illegal_state_exception", "reason"=>"Can't get text on a START_OBJECT at 1:1233"}}}}}
Необходима информация, IP, пользователь, имя ПК, домен, название принтера, имя документа, кол-во. страниц.
п.с. лог взят из logstash-plain