Hi Experts,
Iam using filebeat to feed my logs to Logstash.
Now, I need your help in capturing the occurences of "Sign on Code failed for user" in my logs. Kindly help me with the grok pattern code for it.
My sample log entry is as below -
JVM.128077 (437) [2020-03-31T11:56:24.569 Usercheck] c9qnpn/QLB2UyA 1610670968891559937 - (3) Sign on Code failed for user USERA@xxx.xxx.xxx.xx
Could you please help to fix the below issue.
I tested my grok pattern online and it looks good but when I try to test my config file using below command. I am getting error. I tried changing {} to in the match statement but no luck.
Error - [2020-03-31T16:28:34,635][FATAL][logstash.runner ] The given configuration is invalid. Reason: Expected one of [ \t\r\n], "#", "-", [0-9], [A-Za-z_], '"', "'", "}" at line 12, column 17 (byte 202) after filter {
** grok {**
** match => {**
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.