I am new to Elastic Stack and trying to filter my fail2ban log.
In Grok Debugger I tried to simulate my Grok pattern on my data but have problems with the timestamp. I always get the simulate error: Provided Grok patterns do not match data in the input.
Input:
Feb 25 09:29:09 fail2ban-server[35630]: fail2ban.actions [35630]: NOTICE [postfix-gateways-soft] Ban 2001:41d0:8:ca94::/
SYSLOGTIMESTAMP will consume 'Feb 25 09:29:09'. WORD:src_action will match the following 'fail2ban'. Then there nothing in your pattern to match '-server[35630]: fail2ban.actions'. You need to add to your grok pattern to match that.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.