We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 2933497 commit 5b20614Copy full SHA for 5b20614
recipes/syslog-pri/syslog.conf
@@ -14,11 +14,11 @@ filter {
14
grok {
15
match => { "message" => "<%{POSINT:syslog_pri}>%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
16
add_field => [ "received_at", "%{@timestamp}" ]
17
- add_field => [ "received_from", "%{@source_host}" ]
+ add_field => [ "received_from", "%{host}" ]
18
}
19
syslog_pri { }
20
date {
21
- match => { "syslog_timestamp" => [ "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ] }
+ match => [ "syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]
22
23
if !("_grokparsefailure" in [tags]) {
24
mutate {
0 commit comments