Hi,
I am having a multiline text file with multiple events, I want to read a particular event from a file.
First, I want to know how can I read this particular multiline text file in filebeat
then after how can i extract particular event from file
Hi,
I am having a multiline text file with multiple events, I want to read a particular event from a file.
First, I want to know how can I read this particular multiline text file in filebeat
then after how can i extract particular event from file
Creating test data...
ServerManagement WebService
[Address] = 127.0.0.1, [Port] = 8080, [RelativeURI] = project24/services/ManagementService, [Compression] = None, [SecurityMode] = None, [CertIssuer] = , [CertSubject] = , [CertSerialNumber] = , [MaxArrayLength] = 2147483647, [MaxBytesPerRead] = 4096, [MaxDepth] = 2147483647, [MaxNameTableCharCount] = 2147483647, [MaxStringContentLength] = 2147483647, [MaxBufferPoolSize] = 524288, [MaxBufferSize] = 524288, [MaxReceivedMessageSize] = 524288, [OpenTimeout] = 180, [CloseTimeout] = 180, [SendTimeout] = 180, [ReceiveTimeout] = 600, [MutualAuthentication] = False, [CertificateHash] =
ClientManagement WebService
[Address] = 127.0.0.1, [Port] = 9090, [RelativeURI] = project24/aptra/unifiedagent/clientmgmt/server, [Compression] = None, [SecurityMode] = None, [CertIssuer] = , [CertSubject] = , [CertSerialNumber] = , [MaxArrayLength] = 2147483647, [MaxBytesPerRead] = 4096, [MaxDepth] = 2147483647, [MaxNameTableCharCount] = 2147483647, [MaxStringContentLength] = 2147483647, [MaxBufferPoolSize] = 524288, [MaxBufferSize] = 524288, [MaxReceivedMessageSize] = 524288, [OpenTimeout] = 180, [CloseTimeout] = 180, [SendTimeout] = 180, [ReceiveTimeout] = 600, [MutualAuthentication] = False, [CertificateHash] =
serverMgmtHost_Opening
serverMgmtHost_Opened
---------- Construct Client ----------
[Address] = 127.0.0.1, [Port] = 9090, [RelativeURI] = project24/aptra/unifiedagent/clientmgmt/server, [Compression] = None, [SecurityMode] = None, [CertIssuer] = , [CertSubject] = , [CertSerialNumber] = , [MaxArrayLength] = 2147483647, [MaxBytesPerRead] = 4096, [MaxDepth] = 2147483647, [MaxNameTableCharCount] = 2147483647, [MaxStringContentLength] = 2147483647, [MaxBufferPoolSize] = 524288, [MaxBufferSize] = 524288, [MaxReceivedMessageSize] = 524288, [OpenTimeout] = 180, [CloseTimeout] = 180, [SendTimeout] = 180, [ReceiveTimeout] = 600, [MutualAuthentication] = False, [CertificateHash] =
11/18/2019 4:46:49 PM Received Message from 127.0.0.1: SubscribedEventOccurred
sequenceNum = 52
terminal = TerminalInfo
Address = 127.0.0.1
UniqueId = 4260ad98-0ecc-46e8-a286-e7b7eb9050a6
CustomerCode = Undefined
Properties =
[0] [TerminalId] = Developer-PC-0
[1] [MACAddress] = 00:00:00:00:00:00
[2] [MachineName] = Developer-PC
[3] [UAVersion] = 04.06.00.01
[4] [GUID] = 4260ad98-0ecc-46e8-a286-e7b7eb9050a6
[5] [IPAddress] = 127.0.0.1
[6] [CustomerCode] = Undefined
CollectorInfo =
[0] [Version] = 1.0.0.3
eventName = NCR.APTRA.Reboot.Complete
eventDetails =
[0] = ManagementEventInfo
ClassUri = NCR.APTRA.Reboot.Complete
Properties =
[0] [WindowsRebootEventID] = 1074
[1] [WindowsRebootReason] = Recovery Reboot due to CX AGENT ISSUE
Reason Code: 0x80020003
Shutdown Type: restart
Comment:
[2] [WindowsRebootUTCEventTimestamp] = 12/10/2019 3:00:00 AM
[3] [TriggerEventUri] = NCR.APTRA.IMgmtServerComms.UANullptr
[4] [TriggerEventSequenceNumber] = 0
[5] [TriggerUTCTimestamp] = NCR.APTRA.IMgmtServerComms.UANullptr
[6] [UTCTimeStamp] = 12/10/2019 6:03:56 AM
classDetails =
documentFragment = Document
Uri =
InstanceName =
Command = RebuildAndRetrieve (0)
Data =
================================================================================
11/18/2019 4:48:09 PM Received Message from 127.0.0.1: DocumentUpload
terminal = TerminalInfo
Address = 127.0.0.1
UniqueId = 4260ad98-0ecc-46e8-a286-e7b7eb9050a6
CustomerCode = Undefined
Properties =
[0] [TerminalId] = Developer-PC-0
[1] [MACAddress] = 00:00:00:00:00:00
[2] [MachineName] = Developer-PC
[3] [UAVersion] = 04.06.00.01
[4] [GUID] = 4260ad98-0ecc-46e8-a286-e7b7eb9050a6
[5] [IPAddress] = 127.0.0.1
[6] [CustomerCode] = Undefined
CollectorInfo =
[0] [Version] = 2.17.0.1
result = RequestResult
Status = Success
requestId = 0
classUri = NCR.APTRA.InventoryCollector.AggregateInventory
instanceName = Default
documentFragment = Document
Uri = NCR.APTRA.InventoryCollector.AggregateInventory
InstanceName = Default
Command = RetrieveDelta (2)
Data = <?xml version="1.0" encoding="utf-8"?><Removed /
================================================================================
11/18/2019 4:46:49 PM Received Message from 127.0.0.1: SubscribedEventOccurred
sequenceNum = 52
terminal = TerminalInfo
Address = 127.0.0.1
UniqueId = 4260ad98-0ecc-46e8-a286-e7b7eb9050a6
CustomerCode = Undefined
Properties =
[0] [TerminalId] = Developer-PC-0
[1] [MACAddress] = 00:00:00:00:00:00
[2] [MachineName] = Developer-PC
[3] [UAVersion] = 04.06.00.01
[4] [GUID] = 4260ad98-0ecc-46e8-a286-e7b7eb9050a6
[5] [IPAddress] = 127.0.0.1
[6] [CustomerCode] = Undefined
CollectorInfo =
[0] [Version] = 1.0.0.3
eventName = NCR.APTRA.Reboot.Complete
eventDetails =
[0] = ManagementEventInfo
ClassUri = NCR.APTRA.Reboot.Complete
Properties =
[0] [WindowsRebootEventID] = 1074
[1] [WindowsRebootReason] = Recovery Reboot due to CX AGENT ISSUE
Reason Code: 0x80020003
Shutdown Type: restart
Comment:
[2] [WindowsRebootUTCEventTimestamp] = 14/10/2019 5:30:00 AM
[3] [TriggerEventUri] = NCR.APTRA.IMgmtServerComms.UANullptr
[4] [TriggerEventSequenceNumber] = 0
[5] [TriggerUTCTimestamp] = NCR.APTRA.IMgmtServerComms.UANullptr
[6] [UTCTimeStamp] = 14/10/2019 6:03:56 AM
classDetails =
documentFragment = Document
Uri =
InstanceName =
Command = RebuildAndRetrieve (0)
Data =
You will need an ingest pipeline to process the log files. In the ingest pipeline you can define all potential fields.
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.