Hi,
I am having a multiline text file with multiple events, I want to read a particular event from a file.
First, I want to know how can I read this particular multiline text file in filebeat
then after how can i extract particular event from file
Hi,
I am having a multiline text file with multiple events, I want to read a particular event from a file.
First, I want to know how can I read this particular multiline text file in filebeat
then after how can i extract particular event from file
Creating test data...
ServerManagement WebService
[Address] = 127.0.0.1, [Port] = 8080, [RelativeURI] = project24/services/ManagementService, [Compression] = None, [SecurityMode] = None, [CertIssuer] = , [CertSubject] = , [CertSerialNumber] = , [MaxArrayLength] = 2147483647, [MaxBytesPerRead] = 4096, [MaxDepth] = 2147483647, [MaxNameTableCharCount] = 2147483647, [MaxStringContentLength] = 2147483647, [MaxBufferPoolSize] = 524288, [MaxBufferSize] = 524288, [MaxReceivedMessageSize] = 524288, [OpenTimeout] = 180, [CloseTimeout] = 180, [SendTimeout] = 180, [ReceiveTimeout] = 600, [MutualAuthentication] = False, [CertificateHash] =
ClientManagement WebService
[Address] = 127.0.0.1, [Port] = 9090, [RelativeURI] = project24/aptra/unifiedagent/clientmgmt/server, [Compression] = None, [SecurityMode] = None, [CertIssuer] = , [CertSubject] = , [CertSerialNumber] = , [MaxArrayLength] = 2147483647, [MaxBytesPerRead] = 4096, [MaxDepth] = 2147483647, [MaxNameTableCharCount] = 2147483647, [MaxStringContentLength] = 2147483647, [MaxBufferPoolSize] = 524288, [MaxBufferSize] = 524288, [MaxReceivedMessageSize] = 524288, [OpenTimeout] = 180, [CloseTimeout] = 180, [SendTimeout] = 180, [ReceiveTimeout] = 600, [MutualAuthentication] = False, [CertificateHash] =
serverMgmtHost_Opening
serverMgmtHost_Opened
---------- Construct Client ----------
[Address] = 127.0.0.1, [Port] = 9090, [RelativeURI] = project24/aptra/unifiedagent/clientmgmt/server, [Compression] = None, [SecurityMode] = None, [CertIssuer] = , [CertSubject] = , [CertSerialNumber] = , [MaxArrayLength] = 2147483647, [MaxBytesPerRead] = 4096, [MaxDepth] = 2147483647, [MaxNameTableCharCount] = 2147483647, [MaxStringContentLength] = 2147483647, [MaxBufferPoolSize] = 524288, [MaxBufferSize] = 524288, [MaxReceivedMessageSize] = 524288, [OpenTimeout] = 180, [CloseTimeout] = 180, [SendTimeout] = 180, [ReceiveTimeout] = 600, [MutualAuthentication] = False, [CertificateHash] =
11/18/2019 4:46:49 PM Received Message from 127.0.0.1: SubscribedEventOccurred
sequenceNum = 52
terminal = TerminalInfo
Address = 127.0.0.1
UniqueId = 4260ad98-0ecc-46e8-a286-e7b7eb9050a6
CustomerCode = Undefined
Properties =
[0] [TerminalId] = Developer-PC-0
[1] [MACAddress] = 00:00:00:00:00:00
[2] [MachineName] = Developer-PC
[3] [UAVersion] = 04.06.00.01
[4] [GUID] = 4260ad98-0ecc-46e8-a286-e7b7eb9050a6
[5] [IPAddress] = 127.0.0.1
[6] [CustomerCode] = Undefined
CollectorInfo =
[0] [Version] = 1.0.0.3
eventName = NCR.APTRA.Reboot.Complete
eventDetails =
[0] = ManagementEventInfo
ClassUri = NCR.APTRA.Reboot.Complete
Properties =
[0] [WindowsRebootEventID] = 1074
[1] [WindowsRebootReason] = Recovery Reboot due to CX AGENT ISSUE
Reason Code: 0x80020003
Shutdown Type: restart
Comment:
[2] [WindowsRebootUTCEventTimestamp] = 12/10/2019 3:00:00 AM
[3] [TriggerEventUri] = NCR.APTRA.IMgmtServerComms.UANullptr
[4] [TriggerEventSequenceNumber] = 0
[5] [TriggerUTCTimestamp] = NCR.APTRA.IMgmtServerComms.UANullptr
[6] [UTCTimeStamp] = 12/10/2019 6:03:56 AM
classDetails =
documentFragment = Document
Uri =
InstanceName =
Command = RebuildAndRetrieve (0)
Data =
================================================================================
11/18/2019 4:48:09 PM Received Message from 127.0.0.1: DocumentUpload
terminal = TerminalInfo
Address = 127.0.0.1
UniqueId = 4260ad98-0ecc-46e8-a286-e7b7eb9050a6
CustomerCode = Undefined
Properties =
[0] [TerminalId] = Developer-PC-0
[1] [MACAddress] = 00:00:00:00:00:00
[2] [MachineName] = Developer-PC
[3] [UAVersion] = 04.06.00.01
[4] [GUID] = 4260ad98-0ecc-46e8-a286-e7b7eb9050a6
[5] [IPAddress] = 127.0.0.1
[6] [CustomerCode] = Undefined
CollectorInfo =
[0] [Version] = 2.17.0.1
result = RequestResult
Status = Success
requestId = 0
classUri = NCR.APTRA.InventoryCollector.AggregateInventory
instanceName = Default
documentFragment = Document
Uri = NCR.APTRA.InventoryCollector.AggregateInventory
InstanceName = Default
Command = RetrieveDelta (2)
Data = <?xml version="1.0" encoding="utf-8"?><Removed /
================================================================================
11/18/2019 4:46:49 PM Received Message from 127.0.0.1: SubscribedEventOccurred
sequenceNum = 52
terminal = TerminalInfo
Address = 127.0.0.1
UniqueId = 4260ad98-0ecc-46e8-a286-e7b7eb9050a6
CustomerCode = Undefined
Properties =
[0] [TerminalId] = Developer-PC-0
[1] [MACAddress] = 00:00:00:00:00:00
[2] [MachineName] = Developer-PC
[3] [UAVersion] = 04.06.00.01
[4] [GUID] = 4260ad98-0ecc-46e8-a286-e7b7eb9050a6
[5] [IPAddress] = 127.0.0.1
[6] [CustomerCode] = Undefined
CollectorInfo =
[0] [Version] = 1.0.0.3
eventName = NCR.APTRA.Reboot.Complete
eventDetails =
[0] = ManagementEventInfo
ClassUri = NCR.APTRA.Reboot.Complete
Properties =
[0] [WindowsRebootEventID] = 1074
[1] [WindowsRebootReason] = Recovery Reboot due to CX AGENT ISSUE
Reason Code: 0x80020003
Shutdown Type: restart
Comment:
[2] [WindowsRebootUTCEventTimestamp] = 14/10/2019 5:30:00 AM
[3] [TriggerEventUri] = NCR.APTRA.IMgmtServerComms.UANullptr
[4] [TriggerEventSequenceNumber] = 0
[5] [TriggerUTCTimestamp] = NCR.APTRA.IMgmtServerComms.UANullptr
[6] [UTCTimeStamp] = 14/10/2019 6:03:56 AM
classDetails =
documentFragment = Document
Uri =
InstanceName =
Command = RebuildAndRetrieve (0)
Data =
You will need an ingest pipeline to process the log files. In the ingest pipeline you can define all potential fields.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.