I'm very new to creating Grok filters and I was going to create one for /var/log/messages (For named). Here is my logstash configuration I attempted to use:
I'm not 100% sure what the issue is. Also, I tried using Automatic grok discovery to come up with this grok filter but as mentioned above this is very new to me. Thank you for any and all help in advanced and let me know if anything else is needed to help assist so I can send it as soon as possible.
Thank you very much for your reply. So, based off of what you said I tried a new one and also passed it along the Grok Debugger and came up with the following:
When I restarted logstash I can see the logs coming in with more fields and options compared to before but I'm still seeing the tags with the parse failures. Is it because it is not grabbing the full line in the pattern? Compared to before, I can grab much more data from the logs. I guess the question for me now is that although the above is a bit better will those tags be an issue?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.