Hi guys i am running into issues with the latest 7.4 logstash. my meraki filters are timing out that the message value is too large. I have tried to set a greedydata on the last field type and others. i am sending these to elasticsearch with the output filter.
different net flows
MERAKIALERT %{NOTSPACE}%{SPACE}%{NOTSPACE:[serial]}%{SPACE}%{NOTSPACE:[logsource]}%{SPACE}flows%{NOTSPACE:[netflows]}%{SPACE}%{NOTSPACE:[otherthing]}%{SPACE}src=%{NOTSPACE:[src_ip]}%{SPACE}dst=%{NOTSPACE:[dst_ip]}%{SPACE}mac=%{NOTSPACE:[mac]}%{SPACE}protocol=%{NOTSPACE:[protocol]}%{SPACE}sport=%{NOTSPACE:[src_port]}%{SPACE}dport=%{NOTSPACE:[dst_port]}
MERAKIALERTFLOWS %{NOTSPACE}%{SPACE}%{NOTSPACE:[serial]}%{SPACE}%{NOTSPACE:[logsource]}%{SPACE}%{NOTSPACE}%{SPACE}src=%{NOTSPACE:[src_ip]}%{SPACE}dst=%{NOTSPACE:[dst_ip]}%{SPACE}mac=%{NOTSPACE:[mac]}%{SPACE}protocol=%{NOTSPACE:[protocol]}%{SPACE}sport=%{NOTSPACE:[src_port]}%{SPACE}dport=%{NOTSPACE:[dst_port]}%{SPACE}%{NOtSPACE:[data]}
MERAKIALERTPATTERN %{NOTSPACE}%{SPACE}%{NOTSPACE:[serial]}%{SPACE}%{NOTSPACE:[logsource]}%{SPACE}%{NOTSPACE}%{SPACE}src=%{NOTSPACE:[src_ip]}%{SPACE}dst=%{NOTSPACE:[dst_ip]}%{SPACE}protocol=%{NOTSPACE:[protocol]}%{SPACE}sport=%{NOTSPACE:[src_port]}%{SPACE}dport=%{NOTSPACE:[dst_port]}%{SPACE}%{NOtSPACE:[pattern]}
MERAKIALERTREQUEST %{NOTSPACE}%{SPACE}%{NOTSPACE:[serial]}%{SPACE}%{NOTSPACE:[logsource]}%{SPACE}%{NOTSPACE}%{SPACE}src=%{NOTSPACE:[src]}%{SPACE}dst=%{NOTSPACE:[dst]}%{SPACE}mac=%{NOTSPACE}%{SPACE}%:{URIPATHPARAM:[request]}
MERAKITRANSLATED %{NOTSPACE}%{SPACE}%{NOTSPACE:[serial]}%{SPACE}%{NOTSPACE:[logsource]}%{SPACE}src=%{NOTSPACE:[src_ip]}%{SPACE}dst=%{NOTSPACE:[dst_ip]}%{SPACE}protocol=%{NOTSPACE:[protocol]}%{SPACE}sport=%{NOTSPACE:[src_port]}%{SPACE}dport=%{NOTSPACE:[dst_port]}%{SPACE}translated_dst_ip=%{NOTSPACE:[trans_dst_ip]}%{SPACE}translated_port=%{NOTSPACE:[trans_dst_port]}
][main] Timeout executing grok '%{MERAKIALERTFLOWS}' against field 'message' with value 'Value too large to output (288 bytes)! First 255 chars are: <134>1 1574446937.334809909 PHX_MX250_1 urls src=172.24.1.8:52627 dst=143.166.156.113:80 mac=A4:93:4C:C0:C1:C5 agent='urlgrabber/3.9.1 yum/3.2.29' request: GET http://linux.dell.com/repo/hardware/latest/mirrors.cgi?osname=el6&basearch=x86_64&native=1&dells'!