Drop oslofmt tag from checks
The filebeat does not ship anything tagged with oslofmt, the openstack tag gives us all we need to parse things correctly. Change-Id: I614e4bc5d85559540a9d616407da993ed90de87e
This commit is contained in:
parent
48d7b08773
commit
eb4e6731b5
@ -173,19 +173,17 @@
|
||||
}
|
||||
}
|
||||
} else if "openstack" in [tags] {
|
||||
if "oslofmt" in [tags] {
|
||||
if "Can not find policy directory: policy.d" in [message] {
|
||||
drop { }
|
||||
}
|
||||
grok {
|
||||
match => {
|
||||
"message" => [
|
||||
"^%{TIMESTAMP_ISO8601:logdate}%{SPACE}%{NUMBER:pid}?%{SPACE}?(?<loglevel>AUDIT|CRITICAL|DEBUG|INFO|TRACE|WARNING|ERROR) \[?\b%{NOTSPACE:module}\b\]?%{SPACE}?%{GREEDYDATA:logmessage}?",
|
||||
"^%{CISCOTIMESTAMP:journalddate}%{SPACE}%{SYSLOGHOST:host}%{SPACE}%{SYSLOGPROG:prog}%{SPACE}%{TIMESTAMP_ISO8601:logdate}%{SPACE}%{NUMBER:pid}%{SPACE}%{NOTSPACE:loglevel}%{SPACE}%{NOTSPACE:module}%{SPACE}%{GREEDYDATA:logmessage}"
|
||||
]
|
||||
}
|
||||
add_field => { "received_at" => "%{@timestamp}" }
|
||||
if "Can not find policy directory: policy.d" in [message] {
|
||||
drop { }
|
||||
}
|
||||
grok {
|
||||
match => {
|
||||
"message" => [
|
||||
"^%{TIMESTAMP_ISO8601:logdate}%{SPACE}%{NUMBER:pid}?%{SPACE}?(?<loglevel>AUDIT|CRITICAL|DEBUG|INFO|TRACE|WARNING|ERROR) \[?\b%{NOTSPACE:module}\b\]?%{SPACE}?%{GREEDYDATA:logmessage}?",
|
||||
"^%{CISCOTIMESTAMP:journalddate}%{SPACE}%{SYSLOGHOST:host}%{SPACE}%{SYSLOGPROG:prog}%{SPACE}%{TIMESTAMP_ISO8601:logdate}%{SPACE}%{NUMBER:pid}%{SPACE}%{NOTSPACE:loglevel}%{SPACE}%{NOTSPACE:module}%{SPACE}%{GREEDYDATA:logmessage}"
|
||||
]
|
||||
}
|
||||
add_field => { "received_at" => "%{@timestamp}" }
|
||||
}
|
||||
if "nova" in [tags] {
|
||||
mutate {
|
||||
|
Loading…
x
Reference in New Issue
Block a user