We have got the predefined grok expressions EMAILADDRESS and QUOTEDSTRING available in elasticsearch/kibana
In my log I have the pattern
fromemailid="shi@gmail.com" toemailid="ela@gmail.com"
What is the best way to represent them so that elasitcsearch can give more meaningful information
fromemailid=%{QUOTEDSTRING,frommail} toemailid=%{QUOTEDSTRING,tomail}
or
fromemailid="%{EMAILADDRESS,frommail}" toemailid="%{EMAILADDRESS,tomail}"
or
fromemailid="(?{EMAILADDRESS})" tomailid="(?{EMAILADDRESS})"
.....
or
Are all the above patterns equivalent?
regards
shini