I have been trying to parse / separate the numeric 4 which is microsecond for average response time but doesn't seem to work below is the GROK filter i tried.
Build your expression gradually. Start with the simplest possible, like %{IPORHOST:clientip} and add more and more until your done or until something breaks.
Ya thanks, I have it now but my problem is when I apply this in logstash.conf file inside filter section the logs aren't appearing. It just stops.
This works fine while debugging in GROK debugger.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.