PPP logs are not useful to me in logstash . I am using the elk stack to manage logs of my MikroTik routers, and I'm having a lot of trouble . From the mikrotik get multiple logs , already are all going to Kibana , but now I just need to keep the logs of type PPP , PPPoE are stored in the database . Except that all the logs comes as a message, such as:
message: pppoe,ppp,info : connected @version:1 @timestamp:August 25th 2016, 11:01:14.990 type:syslog host:220.127.116.11 _id:AVbCATgFx-cjIMIocgLZ _type:syslog _index:logstash-2016.08.25 _score:
This is the log I get the data with PPP , PPPoE ..
Now the example of another log (the log want to keep it )
message:system,error,critical login failure for user ftp from 18.104.22.168 via ftp @version:1 @timestamp:August 25th 2016, 09:31:05.326 type:syslog host:22.214.171.124 _id:AVbBrrASx-cjIMIocfYi _type:syslog _index:logstash-2016.08.25 _score:
In short , I want to prevent the PPP , PPPoE logs, and other logs do not .
Sorry for the bad language , can not speak and read English.