Hello everybody,
I am trying to send to logstack some lines from an event generate in my log file, I don't know how to do that.
Below is an exemple of the event which is generate in my log, what i am trying to send to logstack is only 3 of this line. (the 3 lines in bold).
My problem is that at the end of the event we have similar patterns which cause my problem (I cannot exclude or include because i will have 2 identical lines.)
Exemple of an event in my logs :
09/06/2016 16:31:00 [7] Request from 127.0.0.1
09/06/2016 16:31:00 [7] action=QUERY&outputencoding=UTF8&xmlmeta=true&querysummary=true&minscore=20&securityinfo=MjY0MHx&databasematch=uas%5Fintranetedf%2B&combine=simple%2BREFERENCE%5FFIELD2%2BREFERENCE%5FFIELD3%2BNODEREF&predict=false&sort=Relevance%2BDate&timeoutms=20000&languagetype=frenchUTF8&anylanguage=true&start=1&printfields=F1%2CF3%2CF2%2CI1%2CF7%2CURL%2CDREDATE%2CUSERID&maxresults=10&totalresults=true&summary=context&characters=260&highlight=summaryterms&starttag=%3Cstrong%3E&endtag=%3C%2Fstrong%3E&text=%28EDF%20OR%20%28ELECTRICITE%20DE%20FRANCE%29%29&actionid=c65dec82cbec4b721c5f03ea5936fd12c0bff8c3&fieldtext=BIASVAL%7Bfr%5FFR%2C1%7D%3ABIAS%5FFIELD1%2BAND%2BBIASVAL%7BGed%20Direction%20Groupe%2C%2D20%7D%3AF7 (127.0.0.1)
09/06/2016 16:31:00 [7] L 12071; A 11307; F 1331; S 1447; DL 1331; SL 0; DT 388
09/06/2016 16:31:00 [7] Returning 10 matches
09/06/2016 16:31:00 [7] Generating query summary
09/06/2016 16:31:00 [7] Query complete
09/06/2016 16:31:00 [7] Request completed in 119 ms.
09/06/2016 16:31:01 [6] Request from 127.0.0.1
09/06/2016 16:31:01 [6] action=GETQUERYTAGVALUES&outputencoding=UTF8&minscore=20&securityinfo=MjY0MH&databasematch=uas%5Fintranetedf%2B&combine=simple%2BREFERENCE%5FFIELD2%2BREFERENCE%5FFIELD3%2BNODEREF&sort=DocumentCount&timeoutms=20000&languagetype=frenchUTF8&anylanguage=true&start=1&documentcount=true&fieldname=F3%2CF2%2CF1%2CF6%2CF5%2CF4%2CF10%2CF7&ranges=FIXED%7B%2E%2C16595%2C16778%2C16869%2C16930%2C16954%2C16962%7D%3AF10&text=%28EDF%20OR%20%28ELECTRICITE%20DE%20FRANCE%29%29&actionid=d168b7bb2dc9c63711626344135110a74b29ccc2 (127.0.0.1)
09/06/2016 16:31:01 [6] L 12071; A 11307; F 1331; S 0; DL 1331; SL 0; DT 388
09/06/2016 16:31:01 [6] GetQueryTagValues complete
09/06/2016 16:31:01 [6] Request completed in 75 ms.
For exemple, if I include the lines I want and exclude the line iI don't want in the configuration file, I will have something like this.
What I want is to have only the 3 line in bold.
09/06/2016 16:31:00 [7] action=QUERY&outputencoding=UTF8&xmlmeta=true&querysummary=true&minscore=20&securityinfo=MjY0MHx&databasematch=uas%5Fintranetedf%2B&combine=simple%2BREFERENCE%5FFIELD2%2BREFERENCE%5FFIELD3%2BNODEREF&predict=false&sort=Relevance%2BDate&timeoutms=20000&languagetype=frenchUTF8&anylanguage=true&start=1&printfields=F1%2CF3%2CF2%2CI1%2CF7%2CURL%2CDREDATE%2CUSERID&maxresults=10&totalresults=true&summary=context&characters=260&highlight=summaryterms&starttag=%3Cstrong%3E&endtag=%3C%2Fstrong%3E&text=%28EDF%20OR%20%28ELECTRICITE%20DE%20FRANCE%29%29&actionid=c65dec82cbec4b721c5f03ea5936fd12c0bff8c3&fieldtext=BIASVAL%7Bfr%5FFR%2C1%7D%3ABIAS%5FFIELD1%2BAND%2BBIASVAL%7BGed%20Direction%20Groupe%2C%2D20%7D%3AF7 (127.0.0.1)
09/06/2016 16:31:00 [7] L 12071; A 11307; F 1331; S 1447; DL 1331; SL 0; DT 388
09/06/2016 16:31:00 [7] Request completed in 119 ms.
09/06/2016 16:31:01 [6] L 12071; A 11307; F 1331; S 0; DL 1331; SL 0; DT 388
09/06/2016 16:31:01 [6] Request completed in 75 ms.
Do you have any advice for me, how to do that ?
Thank you in advance for your help.
Yves