Substring logstash


Im use grok patterns to extract info from Palo Alto log. But im try to extract a substring on description field like this

authenticated for user 'newUser'. auth profile 'D', server profile 'LTY', server address '', From:

I want to extract the value next to user, between '' and the IP next to "From" but I dont have idea the correct form.

Any idea?


I would try

grok {
    break_on_match => false
    match => {
        "[message]" => [
            "user '%{USER:username}'"