[英]grok pattern to custom logstash config
^(?:%{LOGLEVEL:level}):\s*%{DATA:message}\s*(?:%{JAVACLASS:caller_class})\s+\[%{WORD:loglevel}\]\s+(\[\s*\S+\s+%{BASE10NUM:tstamp}.*?\]\s+)+(\[\s*\S+\s+%{BASE10NUM:memory}\S*\s+\S+\s+%{BASE10NUM:total}.*?\])
this is my grok pattern from here https://regex101.com/r/yMq9J1/1 这是我在这里的希腊模式https://regex101.com/r/yMq9J1/1
and now I wanted to use this in my logstash config in filter but I get an error 现在我想在过滤器的logstash配置中使用它,但是出现错误
The given configuration is invalid.
指定的配置无效。 Reason: Expected one of #, => at line 12, column 19 (byte 341) after filter { grok { match => { "message" => "^(?:%{LOGLEVEL:level}):\\s*%{DATA:message}\\s*(?:%{JAVACLASS:caller_class})\\s+[%{WORD:loglevel}]\\s+([\\s*\\S+\\s+%{BASE10NUM:tstamp}. ?]\\s+)+([\\s \\S+\\s+%{BASE10NUM:memory}\\S*\\s+\\S+\\s+%{BASE10NUM:total}.*?])" } } output { elasticsearch
原因:过滤器{grok {match => {“ message” =>“ ^(?:%{LOGLEVEL:level}):\\ s *%之后,第12行第19列(字节341)中的#,=>之一{DATA:消息} \\ s *(?:%{JAVACLASS:caller_class})\\ s + [%{WORD:loglevel}] \\ s +([\\ s * \\ S + \\ s +%{BASE10NUM:tstamp}。 ?] \\ s + )+([[\\ s \\ S + \\ s +%{BASE10NUM:memory} \\ S * \\ s + \\ S + \\ s +%{BASE10NUM:total}。*?])“}}输出{elasticsearch
can you guys help me understand the situation here? 你们能帮我了解一下这里的情况吗?
The grok pattern is not the problem, the configuration is missing a }
to close the match setting of the grok filter. grok模式不是问题,配置缺少
}
以关闭grok过滤器的匹配设置。
It should be added after %{BASE10NUM:total}.*?])"
, like this: 应该将其添加到
%{BASE10NUM:total}.*?])"
,如下所示:
...%{BASE10NUM:total}.*?])"
} # missing accolade
}
}
output {
elasticsearch
...
声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.