Unable to dissect logs based on a string pattern

Hello,

this is the filter I am using

filter {
if (([message] =~ /Interface/)) {
dissect {
mapping => { "message" => "%{syslog_timestamp} %{+syslog_timestamp},%{} %{} %{device_type} %{hostname}-%{h1}/%{} %{kernel_logs}" }
}
}
}

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.