bobthomson70

yalc

Jun 15th, 2015
333
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.36 KB | None | 0 0
  1. input {
  2. syslog {
  3. port => 514
  4. type => "syslog"
  5. }
  6. }
  7. filter {
  8. grok {
  9. match => [ 'message', '<%{POSINT:pri}>%{SYSLOGTIMESTAMP:timestamp} %{IPORHOST:hostname} %{WORD:app_name} %{WORD:level} %{GREEDYDATA:message}' ]
  10. add_tag => [ "match1 greedy" ]
  11. tag_on_failure => [ "not a _grokparsefailure_honest" ]
  12. }
  13. }
Advertisement
Add Comment
Please, Sign In to add comment