Drop oslofmt tag from checks
The filebeat does not ship anything tagged with oslofmt, the openstack tag gives us all we need to parse things correctly. Change-Id: I614e4bc5d85559540a9d616407da993ed90de87e
This commit is contained in:
parent
48d7b08773
commit
eb4e6731b5
@ -173,19 +173,17 @@
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
} else if "openstack" in [tags] {
|
} else if "openstack" in [tags] {
|
||||||
if "oslofmt" in [tags] {
|
if "Can not find policy directory: policy.d" in [message] {
|
||||||
if "Can not find policy directory: policy.d" in [message] {
|
drop { }
|
||||||
drop { }
|
}
|
||||||
}
|
grok {
|
||||||
grok {
|
match => {
|
||||||
match => {
|
"message" => [
|
||||||
"message" => [
|
"^%{TIMESTAMP_ISO8601:logdate}%{SPACE}%{NUMBER:pid}?%{SPACE}?(?<loglevel>AUDIT|CRITICAL|DEBUG|INFO|TRACE|WARNING|ERROR) \[?\b%{NOTSPACE:module}\b\]?%{SPACE}?%{GREEDYDATA:logmessage}?",
|
||||||
"^%{TIMESTAMP_ISO8601:logdate}%{SPACE}%{NUMBER:pid}?%{SPACE}?(?<loglevel>AUDIT|CRITICAL|DEBUG|INFO|TRACE|WARNING|ERROR) \[?\b%{NOTSPACE:module}\b\]?%{SPACE}?%{GREEDYDATA:logmessage}?",
|
"^%{CISCOTIMESTAMP:journalddate}%{SPACE}%{SYSLOGHOST:host}%{SPACE}%{SYSLOGPROG:prog}%{SPACE}%{TIMESTAMP_ISO8601:logdate}%{SPACE}%{NUMBER:pid}%{SPACE}%{NOTSPACE:loglevel}%{SPACE}%{NOTSPACE:module}%{SPACE}%{GREEDYDATA:logmessage}"
|
||||||
"^%{CISCOTIMESTAMP:journalddate}%{SPACE}%{SYSLOGHOST:host}%{SPACE}%{SYSLOGPROG:prog}%{SPACE}%{TIMESTAMP_ISO8601:logdate}%{SPACE}%{NUMBER:pid}%{SPACE}%{NOTSPACE:loglevel}%{SPACE}%{NOTSPACE:module}%{SPACE}%{GREEDYDATA:logmessage}"
|
]
|
||||||
]
|
|
||||||
}
|
|
||||||
add_field => { "received_at" => "%{@timestamp}" }
|
|
||||||
}
|
}
|
||||||
|
add_field => { "received_at" => "%{@timestamp}" }
|
||||||
}
|
}
|
||||||
if "nova" in [tags] {
|
if "nova" in [tags] {
|
||||||
mutate {
|
mutate {
|
||||||
|
Loading…
x
Reference in New Issue
Block a user