I do not understand what you are trying to do here. I see nothing that would have created the [LEVEl] field, so I would expect none of the groks to be executed. Also, all of your grok filters look the same, so why not replace that whole filter section with
please help me. here I am trying to extract "ERROR", "DEBUG" and "CRITICAL " logs with the help of logstash and add_field which contain loglevel like ("ERROR", "DEBUG" and "CRITICAL") as per its type.
Avoid to send "INFO" logs to output.
Could you please help how can write filter for that?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.