Advertisement
Guest User

randomconf9000

a guest
Dec 11th, 2015
190
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.92 KB | None | 0 0
  1. input {
  2. file {
  3. path => "/home/htpcguides/syslog/*.log"
  4. start_position => "beginning"
  5. type => "syslog"
  6.  
  7. }
  8. }
  9.  
  10.  
  11. filter {
  12. if [type] == "syslog" {
  13. grok {
  14. break_on_match => false
  15. match => [
  16. "message", "%{TIMESTAMP_ISO8601:@timestamp} (?<message-body>(?<message_system_info>(?:\[%{DATA:message_thread_id} %{DATA:syslog_level} \'%{DATA:message_service}\'\ ?%{DATA:message_opID}])) \[%{DATA:message_service_info}]\ (?<message-syslog>(%{GREEDYDATA})))",
  17. "message", "%{TIMESTAMP_ISO8601:@timestamp} (?<message-body>(?<message_system_info>(?:\[%{DATA:message_thread_id} %{DATA:syslog_level} \'%{DATA:message_service}\'\ ?%{DATA:message_opID}])) (?<message-syslog>(%{GREEDYDATA})))",
  18. "message", "<%{POSINT:syslog_pri}>%{TIMESTAMP_ISO8601:@timestamp} %{GREEDYDATA:message-syslog}"
  19. ]}
  20. }
  21. }
  22.  
  23. output {
  24. elasticsearch { hosts => ["localhost:9200"] }
  25. stdout { codec => rubydebug }
  26. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement