This looks like the syslog format, which is more suitable grok in case you have optional fields.
Is this 3 types of grok patterns in the same matching or you have 3 different syslog sources and the grok patterns?
the sources are differents.
In the pipeline from which these grok come, the output is an index elk.
I wonder if it would be more logic to use http filter in that case and write directly in the index?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.