I am importing IIS logs from the SMTP relay service. I have successfully separated out all of the fields in logstash. One of the data fields needs to have excess characters trimmed and then converted to lower case for the report grouping to display correctly.
Ok, I have figured out how to parse the field with grok
grok {
match => { "CS-URI-Query" => "(?[+A-Z][:][<])%{EMAILADDRESS:themail}%{GREEDYDATA:DropMe2}"}
}
This gives me a field, the mail, with the embedded email address. Now on to the next issue....
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.