Parsing log with "@" as token

(Gustav Gonzalez) #1

I'm having a hard time parsing a log with this configuration:




I am using this grok expression:

match => "%{DATA:username}/%{DATA:user_id}\@%{DATA:domain}"

But the "domain" variable is always lost. Any suggestion to get the three values in a clean way?

(Gustav Gonzalez) #2

Finally I could solve it using this grok expression:

match => "%{DATA:username}/%{USER:user_id}@%{HOSTNAME:domain}"

(Magnus B├Ąck) #3

Yeah, be very careful with more than one DATA or GREEDYDATA in the same expressions. Use stricter patterns whenever you can.

(system) #4