Hmm..have facing challenges and need help with. I am not able to map DAYMONTH which is beginning at the line. And then brackets at the end for IP addresses.
client %{IPV4:clientip}#%{POSINT:clientport} (%{GREEDYDATA:query}): query: %{GREEDYDATA:Target} IN %{GREEDYDATA:querytype} (%{IPV4:src_ip}) --> This does not match
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.