Hello I am trying to parse log file and wanted to check how I can stop at first encounter of ":" for Tag.
02-05 00:00:13.199 3162 3162 I audit : test: Loaded service_contexts from /service_contexts.
Grok filter I have added for this: %{MONTHNUM:Month}-%{MONTHDAY:Day}\s*%{TIME:Timestamp}\s*%{NONNEGINT:SID}\s*%{NUMBER:R_id}\s*%{WORD:Severity}\s*(?(?:[()a-zA-Z0-9./[^ ]\s]+)):\s*%{GREEDYDATA:Message}
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.