Not getting grok pattern for 12/11/2013 8:30:48 AM


(vani) #1

Hi All,
can any one help grok pattern for following logs.i tried for the below logs but i am getting difficulty during am/pm.please help me.

My logs:
Started : 12/11/2013 8:30:48 AM
Finished (1) : 12/11/2013 8:30:48 AM
´╗┐Started : 3/12/2014 4:00:49 PM
[2] Deductions Transfer Failed - Deduction already exists: Acct: 28511265 , Number : 0001487209, Value : 264889.05
Finished (1) : 3/12/2014 4:00:59 PM


(Shaunak Kashyap) #2

I think this pattern should match 12/11/2013 8:30:48 AM:

%{MONTHNUM:month}/%{MONTHDAY:day}/%{YEAR:year} %{HOUR:hour}:%{MINUTE:minute}:%{SECOND:seconds} %{NOTSPACE:ampm}

You can test grok patterns at https://grokdebug.herokuapp.com/.


(system) #3