Unable to parse Meraki MX

(Frank Shearer) #1

Hi All,

I'm having an issue maybe someone can help me out with, I am trying to parse Meraki flows messages which look like this:

my input conf is this:

and my filter conf is this:

I continually get this in stdout when testing and I have verified the gork works using grokconstructor.

Can someone tell me what I am doing wrong? Thanks

(Frank Shearer) #2

I figured it out, all I did was move everything inside the filter statement and did the logic from there. Thanks

